Certification Course · Executive Leadership Track

Certified Chief AI Governance Officer (CCAIGO).

The executive credential for leaders who own AI risk, compliance and ethics at the highest level. Delivered through Authorized Training Partners, assessed independently by AICA, and issued with a verifiable digital badge.

Exam Specification

The Specification, on the Record.

Certifying a team instead? Explore workforce certification →

CredentialCertified Chief AI Governance Officer (CCAIGO)
TrackExecutive Leadership Track
Assessment formatCase-based examination (60%) and a governance framework submission (40%)
Contact hours24 contact hours across three consecutive or split days
Certification feeUSD 2,400
Validity3 years from award date
Renewal60 CPD hours per 3-year cycle, logged with AICA
Retake policyReattempt after a 14 day waiting period, up to 3 attempts in any 12 months
DeliveryThrough Authorized Training Partners, online or center-based
VerificationCryptographic registry entry, QR-verifiable digital badge, Open Badges 3.0

Exam duration and question counts are set in the Candidate Handbook and are not published here. The full proctoring, retake, appeals, renewal and revocation terms are on the exam policies page.

Course Overview

The Standard for Enterprise AI Governance.

The CCAIGO certification course prepares senior leaders for the Certified Chief AI Governance Officer credential, AICA's executive certification for those who own AI risk, compliance and ethics at the highest level of the organization. It validates the capability to design and operate enterprise AI governance, aligning innovation with regulation, assurance and public trust.

As AI regulation hardens worldwide, from the EU AI Act to national frameworks and international standards, organizations need an executive who can turn legal text into working controls, and working controls into evidence a regulator will accept. The CCAIGO gives that role a defined, independently assessed standard, so boards, regulators and the public can see that AI governance is held by someone whose competence has been verified.

The CCAIGO is part of the Executive Leadership Track in the AICA certification portfolio. Like every AICA credential, it follows a governed process in which standards, training and assessment are deliberately separated. The full model is set out on the How It Works page.

Who It Is For

  • Chief AI Governance Officers and heads of responsible AI
  • Chief risk, compliance and audit executives extending into AI
  • General counsel and senior legal leaders owning AI regulatory exposure
  • Senior leaders building an enterprise AI governance function

The Mandate It Validates

Ownership of AI risk, compliance and ethics at enterprise level: designing the governance system, operating it credibly, and answering for it before boards and regulators.

Competency Domains

Six Domains. One Standard of Competence.

The CCAIGO competency framework is built on six domains. Certification confirms demonstrated capability in each, assessed against predefined benchmarks rather than attendance.

01

AI Governance Frameworks & Operating Models

Certified leaders can design an enterprise AI governance framework from first principles: committees, decision rights, controls and reporting lines. They can size it to the organization and keep it operating once the launch attention fades.

02

Global AI Regulation & Standards: EU AI Act, NIST AI RMF, ISO/IEC 42001

Holders can interpret the major regulatory and standards instruments, determine which obligations apply to their organization, and translate them into concrete controls, documentation and timelines rather than abstract policy statements.

03

AI Risk Management & Assurance

Holders can build and run an AI risk taxonomy: identifying, assessing and treating model and system risk across the estate. They can commission assurance work, challenge its findings, and decide when residual risk is acceptable.

04

Responsible AI Policy Design & Enforcement

Holders can write responsible AI policy that people can actually follow, embed it into delivery and procurement, and enforce it consistently, including handling exceptions and escalations without eroding the policy's authority.

05

AI Audit Readiness & Documentation

Holders can keep the organization permanently audit-ready: maintaining model documentation, decision records and evidence trails so that an internal or external audit finds a working system, not a scramble.

06

Board & Regulator Engagement

Holders can represent the organization's AI governance posture to boards and regulators with candour and precision. They can report bad news early, defend judgments under questioning, and sustain trust on both sides.

Course Curriculum

Twenty Four Contact Hours. Six Learning Units.

The CCAIGO curriculum turns the six competency domains into six Learning Units, delivered over three days in an executive cohort format. Teaching is built on facilitated casework, framework working sessions and directed discussion rather than lecture, because the credential assesses judgment, not recall.

Format

24 contact hours across three consecutive or split days, delivered to a small executive cohort by an Authorized Training Partner.

Assessment

Case-based examination (60%) and a governance framework submission (40%): a working AI governance framework artifact prepared for the candidate's own organization or a simulated one.

Intended Candidates

Executives who own AI risk, compliance or ethics. Senior governance, risk, legal or compliance leadership experience is recommended.

Course-Level Learning Objectives

On completion, candidates are able to:

  1. CLO1 Design an enterprise AI governance framework, including committee structures, decision rights, controls and reporting lines, proportionate to the organization's scale and risk profile. Domain 1
  2. CLO2 Evaluate the organization's obligations under the EU AI Act's risk-based classification and direct a compliance response appropriate to each tier. Domain 2
  3. CLO3 Operationalize the NIST AI Risk Management Framework functions of Govern, Map, Measure and Manage as a working risk practice across the AI estate. Domains 2 and 3
  4. CLO4 Direct the establishment of an AI management system consistent with the logic of ISO/IEC 42001, connecting policy, operation, performance evaluation and improvement. Domains 2 and 5
  5. CLO5 Evaluate AI risk assessments and assurance findings, and decide on the acceptance of residual risk with a defensible record. Domain 3
  6. CLO6 Design responsible AI policy and enforce it consistently, including the handling of exceptions and escalations. Domain 4
  7. CLO7 Direct an audit-readiness discipline in which model documentation, decision records and evidence trails are maintained as a permanent operating state. Domain 5
  8. CLO8 Defend the organization's AI governance posture before boards and regulators, including the early and honest reporting of adverse findings. Domain 6
LU1

AI Governance Frameworks & Operating Models

4 Hours

Delivery: facilitated case discussion and a framework drafting studio in which the cohort designs operating model components against a live scenario.

Domain 1 · Supports CLO1

Learning Outcomes

By the end of this unit, learners are able to:

  • LO 1.1 Design an enterprise AI governance operating model, including committee structures, decision rights, escalation paths and reporting lines.
    Assessment criteria:
    • Produces an operating model design in which committee mandates, decision rights and reporting lines are assigned to named roles with no gaps and no overlaps.
    • Justifies the chosen structure against at least one rejected alternative, with reference to the organization's scale and risk profile.
  • LO 1.2 Evaluate an existing governance arrangement against the organization's scale and AI risk profile, and recommend proportionate change.
    Assessment criteria:
    • Identifies the material weaknesses in a given governance arrangement and links each to a specific consequence for oversight.
    • Recommends changes that are proportionate to the stated scale and risk profile rather than defaulting to a maximal template.
  • LO 1.3 Plan the sustained operation of the framework, including meeting cadence, resourcing and management review, beyond its initial launch.
    Assessment criteria:
    • Prepares an operating calendar in which meeting cadence, resourcing and management review are specified and mutually consistent.
    • Defines the triggers that would prompt revision of the framework outside the scheduled review cycle.

Attitude, Skills, Knowledge (A.S.K.)

DimensionWhat the Unit Develops and Assesses
Attitude
  • Independence of judgment when governance conclusions are commercially unwelcome
  • Ownership of the governance mandate rather than delegation of accountability
  • Proportionality: resisting governance theater as firmly as governance neglect
Skills
  • Design committee structures and decision rights matrices appropriate to organizational scale
  • Draft governance charters and terms of reference that assign accountability by name
  • Integrate AI governance with existing risk, data and security governance rather than duplicating it
  • Establish escalation paths that surface issues to the accountable executive before they harden
  • Plan management review cycles that keep the framework operating after launch attention fades
Knowledge
  • The principal AI governance operating models and their trade-offs: centralized, federated, hub and spoke
  • The distinction between accountability, which cannot be delegated, and responsibility, which can
  • The three lines model as applied to AI oversight
  • ISO/IEC 42001 management-system logic: policy, roles, planning, operation, performance evaluation and improvement as one connected cycle
LU2

Global AI Regulation & Standards: EU AI Act, NIST AI RMF, ISO/IEC 42001

5 Hours

Delivery: regulatory mapping workshop worked directly against the instruments, with facilitated case discussion on classification and obligation calls.

Domain 2 · Supports CLO2, CLO3 and CLO4

Learning Outcomes

By the end of this unit, learners are able to:

  • LO 2.1 Evaluate which EU AI Act obligations apply to the organization, based on its role in the AI value chain and the risk classification of each system.
    Assessment criteria:
    • Classifies the AI systems in a case scenario into the correct EU AI Act risk tiers, with a stated rationale for each classification.
    • Identifies the organization's role in the value chain for each system and states the obligations that follow from that role.
  • LO 2.2 Operationalize the NIST AI RMF and ISO/IEC 42001 alongside binding regulation as a single, coherent compliance position.
    Assessment criteria:
    • Produces a compliance position in which NIST AI RMF functions and ISO/IEC 42001 requirements are mapped to binding obligations without duplicated controls.
    • Distinguishes correctly between what is legally required and what is voluntarily adopted, and records the basis for each.
  • LO 2.3 Translate regulatory and standards requirements into concrete controls, documentation and delivery timelines.
    Assessment criteria:
    • Converts a set of regulatory requirements into named controls, each with an owner, an evidence requirement and a delivery date.
    • Sequences the resulting delivery timeline so that dependencies between controls are respected.

Attitude, Skills, Knowledge (A.S.K.)

DimensionWhat the Unit Develops and Assesses
Attitude
  • Fidelity to the legal text over vendor summaries and secondhand commentary
  • Disclosure honesty when an obligation is not yet met
  • Restraint in claiming compliance before the evidence exists
Skills
  • Classify AI systems against the EU AI Act's risk-based tiers, from prohibited practices through high-risk obligations to transparency duties and minimal-risk systems
  • Map organizational roles in the AI value chain, such as provider and deployer, to their distinct obligations
  • Stand up the NIST AI RMF functions of Govern, Map, Measure and Manage as operating practices rather than headings
  • Align existing controls to ISO/IEC 42001 management-system requirements without building a parallel bureaucracy
  • Maintain a regulatory horizon watch and brief the executive on material change
Knowledge
  • The EU AI Act's risk-based structure: prohibited practices, high-risk systems and their lifecycle obligations, transparency obligations, and duties attaching to general-purpose AI models
  • The NIST AI RMF's four functions and its treatment of trustworthiness characteristics such as validity, safety, fairness and transparency
  • ISO/IEC 42001 as a certifiable AI management-system standard built on a plan, do, check, act discipline
  • How voluntary frameworks and binding regulation interact within one compliance position
LU3

AI Risk Management & Assurance

5 Hours

Delivery: risk register working session and an assurance findings clinic in which the cohort challenges real-format assurance reports and defends residual-risk decisions.

Domain 3 · Supports CLO3 and CLO5

Learning Outcomes

By the end of this unit, learners are able to:

  • LO 3.1 Design an AI risk taxonomy and assessment methodology covering model, data, deployment and third-party risk across the estate.
    Assessment criteria:
    • Produces a risk register entry in which classification, owner, control and review date are complete and internally consistent.
    • Applies the taxonomy across model, data, deployment and third-party risk without gaps in coverage.
  • LO 3.2 Evaluate assurance findings, challenge their scope and rigor, and decide when residual risk is acceptable.
    Assessment criteria:
    • Challenges the scope or rigor of a given assurance report and identifies what further evidence a sound decision requires.
    • Records a residual-risk acceptance decision with a rationale that an independent reviewer could reconstruct and defend.
  • LO 3.3 Direct risk treatment and continuous monitoring so that risk decisions remain current as systems and usage change.
    Assessment criteria:
    • Assigns treatment actions with owners and target dates, and states the monitoring signal that would show each treatment is working.
    • Specifies the conditions under which a previously accepted risk must return for a fresh decision.

Attitude, Skills, Knowledge (A.S.K.)

DimensionWhat the Unit Develops and Assesses
Attitude
  • Skepticism toward assurance that arrives without evidence
  • Willingness to make the residual-risk decision and be answerable for it
  • Consistency of risk ratings under commercial pressure to soften them
Skills
  • Build and maintain an AI risk register with named ownership and review dates
  • Apply the NIST AI RMF cycle of Map, Measure and Manage to individual systems and to the portfolio
  • Commission internal or external assurance with a scope that tests what matters
  • Interrogate evaluation results, including bias testing, robustness and performance drift, as a decision-maker rather than a technician
  • Draft risk appetite and tolerance statements a board can endorse
Knowledge
  • The categories of AI-specific risk: data quality and provenance, model behavior including bias, robustness and drift, misuse, and third-party model supply
  • The distinction between inherent and residual risk, and where treatment sits between them
  • The types of assurance and their relative reliability: self-assessment, internal audit, independent external review
  • The Govern function as the precondition on which the other three NIST AI RMF functions depend
LU4

Responsible AI Policy Design & Enforcement

3 Hours

Delivery: policy drafting studio followed by facilitated exception-handling scenarios in which the cohort rules on requests from senior stakeholders.

Domain 4 · Supports CLO6

Learning Outcomes

By the end of this unit, learners are able to:

  • LO 4.1 Design responsible AI policy that practitioners can follow and the organization can enforce.
    Assessment criteria:
    • Drafts a policy clause in enforceable language, with defined terms and a requirement that can be tested for compliance.
    • States what the policy deliberately does not cover and where those matters are handled instead.
  • LO 4.2 Operationalize policy through delivery, procurement and vendor gates, including a defensible exception and escalation process.
    Assessment criteria:
    • Embeds policy checkpoints at the correct delivery, procurement and vendor management gates for a given case scenario.
    • Processes an exception request with an expiry date, a mandatory review and a record that supports even-handed enforcement.

Attitude, Skills, Knowledge (A.S.K.)

DimensionWhat the Unit Develops and Assesses
Attitude
  • Even-handed enforcement regardless of the seniority of the person requesting an exception
  • Honesty about what a policy does not cover
  • Respect for the practitioners who must live with the policy daily
Skills
  • Draft policy in enforceable language, with defined terms and requirements that can be tested
  • Embed policy checkpoints into delivery, procurement and vendor management gates
  • Design exception processes with expiry dates and mandatory review, so exceptions cannot quietly become the norm
  • Handle escalations in a way that resolves the case without eroding the policy's authority
  • Revise or retire policy on evidence rather than anniversary
Knowledge
  • The policy hierarchy of principles, policy, standard and procedure, and where enforcement actually bites
  • The common failure modes of responsible AI policy: aspiration without controls, exceptions without expiry, enforcement without consistency
  • How policy requirements trace back to regulatory obligations and forward to risk decisions
LU5

AI Audit Readiness & Documentation

4 Hours

Delivery: evidence architecture working session and a mock document production exercise run to the standard an external auditor would apply.

Domain 5 · Supports CLO4 and CLO7

Learning Outcomes

By the end of this unit, learners are able to:

  • LO 5.1 Design a documentation and evidence architecture that keeps the organization permanently audit-ready.
    Assessment criteria:
    • Specifies a documentation set for a given AI system covering purpose, data, testing, limitations and approvals, with an owner for each artifact.
    • Designs the evidence trail so that each risk acceptance can be traced to a contemporaneous record and a named accountable owner.
  • LO 5.2 Evaluate the current evidence trail as an auditor would, identify gaps and direct remediation to closure.
    Assessment criteria:
    • Identifies the gaps in a sample evidence trail that an auditor would raise, and grades their severity credibly.
    • Directs remediation through corrective actions tracked to verified closure rather than to assignment alone.

Attitude, Skills, Knowledge (A.S.K.)

DimensionWhat the Unit Develops and Assesses
Attitude
  • Evidence discipline as a habit of operation, not an event before an audit
  • Candour in acknowledging documentation gaps rather than papering over them
  • Refusal to reconstruct records retrospectively and present them as contemporaneous
Skills
  • Specify model documentation requirements across the lifecycle: purpose, data, testing, limitations and approvals
  • Maintain decision records that link each risk acceptance to a named accountable owner
  • Prepare for and manage internal and external audit engagements, including document production
  • Operate corrective action tracking through to verified closure
  • Keep documentation current as systems, data and usage change
Knowledge
  • What auditors treat as reliable evidence: contemporaneous records, traceability, versioning and controlled access
  • The documentation, logging and record-keeping expectations that attach to high-risk systems under the EU AI Act, described at the level of obligation rather than clause
  • ISO/IEC 42001's performance evaluation and improvement logic, including internal audit and management review
  • The distinction between certification of a management system and assurance of an individual model
LU6

Board & Regulator Engagement

3 Hours

Delivery: mock regulator engagement and a board briefing simulation with structured, testimony-style questioning of each candidate.

Domain 6 · Supports CLO8

Learning Outcomes

By the end of this unit, learners are able to:

  • LO 6.1 Design board reporting on AI governance that is decision-useful, honest and stable in format over time.
    Assessment criteria:
    • Produces a board report built on a small set of stable indicators, in which adverse findings are stated plainly and early.
    • Presents technical risk to non-technical directors without material distortion in either direction.
  • LO 6.2 Defend governance judgments, including adverse findings, before boards and regulators under questioning.
    Assessment criteria:
    • Defends a governance judgment under structured questioning, conceding the points that should be conceded and holding those that should not.
    • Responds to a simulated regulator request with a production plan that is complete, timely and honest about what does not yet exist.

Attitude, Skills, Knowledge (A.S.K.)

DimensionWhat the Unit Develops and Assesses
Attitude
  • Bad news first: early disclosure over managed optics
  • Composure and precision under hostile questioning
  • Respect for the regulator's mandate without capitulating on well-founded judgment
Skills
  • Construct a board-level AI governance report around a small number of stable indicators
  • Brief non-technical directors on technical risk without distortion in either direction
  • Manage a supervisory engagement or regulatory inquiry, including timelines and document production
  • Defend governance decisions in testimony-style questioning, conceding what should be conceded
  • Correct the record promptly when a previous report is later found to be wrong
Knowledge
  • Board duties and oversight expectations relating to AI, in general terms across major jurisdictions
  • What regulators typically request in a supervisory engagement, and what a credible response looks like
  • The principles of honest reporting under uncertainty, including how to present confidence and its limits
  • The reputational mechanics of disclosure and delay
Assessment Blueprint

How Each Learning Unit Is Assessed.

Every Learning Unit contributes to both assessment components. The case-based examination carries 60% of the overall result and the governance framework submission carries 40%. The blueprint below shows the contribution of each unit.

Learning UnitAssessment ComponentEvidence AssessedWeighting
LU1 · Governance Frameworks & Operating ModelsCase-based examination (10%)
Framework submission (10%)
Operating-model decisions in the case scenarios; the committee structure, decision rights and reporting lines of the submitted framework20%
LU2 · Global AI Regulation & StandardsCase-based examination (14%)
Framework submission (6%)
Risk classification and obligation analysis in the case scenarios; the regulatory mapping within the submitted framework20%
LU3 · AI Risk Management & AssuranceCase-based examination (12%)
Framework submission (8%)
Risk judgments and residual-risk decisions in the case scenarios; the risk taxonomy, appetite statement and assurance plan in the framework20%
LU4 · Responsible AI Policy Design & EnforcementCase-based examination (8%)
Framework submission (6%)
Policy enforcement and exception decisions in the case scenarios; the policy architecture and exception process in the framework14%
LU5 · AI Audit Readiness & DocumentationCase-based examination (8%)
Framework submission (6%)
Audit-readiness judgments in the case scenarios; the documentation and evidence architecture in the framework14%
LU6 · Board & Regulator EngagementCase-based examination (8%)
Framework submission (4%)
Board and regulator scenarios in the examination; the board reporting design in the framework12%
TotalExamination 60% · Framework submission 40%100%
Credential Terms

Terms of the CCAIGO Credential.

TermProvision
Credential validity3 years from award date.
RenewalVia Continuing Professional Development: 60 CPD hours per 3 year cycle, logged with AICA.
Retake policyReattempt after a 14 day waiting period, with a maximum of 3 attempts in any 12 months.
AppealsAssessment decisions may be appealed to AICA's Certification and Standards Authority.
ProctoringExaminations are proctored, delivered online or center based through Authorized Training Partners.
ConductCertification requires agreement to the AICA Code of Professional Conduct.

Curriculum Standard v1.0. Published 10 July 2026. Reviewed annually by the AICA Certification and Standards Authority.

Assessment & Credential

Independently Assessed. Verifiably Credentialed.

01

Assessment Format

The CCAIGO is assessed through a case-based examination and a governance framework submission. Both are designed to test applied governance judgment in realistic scenarios, not recall.

02

Delivery Through Authorized Training Partners

Preparation is delivered worldwide by AICA Authorized Training Partners: approved organizations that teach to the AICA competency framework under consistent quality requirements.

03

Independent Certification Decision

Certification decisions are made by the AICA Certification and Standards Authority, separate from training delivery. The governed, seven-stage process is set out on the How It Works page.

04

Digital Badge & Registry

Successful candidates receive the official CCAIGO digital badge with a unique credential identifier, recorded in the AICA verification registry. Any employer can verify the credential against its live registry record.

Frequently Asked Questions

CCAIGO Course FAQs.

What is the CCAIGO certification course?
The CCAIGO certification course prepares senior leaders for the Certified Chief AI Governance Officer credential, awarded by the Artificial Intelligence Certification Authority (AICA). It covers governance frameworks, global AI regulation and standards, risk management and assurance, responsible AI policy, audit readiness and engagement with boards and regulators.
Who should pursue the CCAIGO?
The CCAIGO is designed for leaders who own AI risk, compliance and ethics at the highest level, including Chief AI Governance Officers, chief risk and compliance officers, heads of responsible AI, and senior counsel taking on the AI governance mandate.
How is the CCAIGO assessed?
The CCAIGO is assessed through a case-based examination and a governance framework submission. All certification decisions are made independently by the AICA Certification and Standards Authority, separate from training delivery.
Which regulations and standards does the CCAIGO cover?
The CCAIGO competency framework addresses global AI regulation and standards, including the EU AI Act, the NIST AI Risk Management Framework and ISO/IEC 42001, with a focus on translating them into a working governance system rather than reciting them.

Ready to Earn the CCAIGO?

The Certified Chief AI Governance Officer program is delivered worldwide through AICA Authorized Training Partners.