The Certified AI Governance Professional (CAIGP) credential, issued by the Artificial Intelligence Certification Authority (AICA), certifies that a professional can implement AI policy, document model risk, map regulatory obligations, control an AI system inventory, prepare for audits, and respond to AI incidents. The assessment combines an examination with an applied governance portfolio, so preparation has to cover both technical recall and the ability to produce real governance artifacts. This guide breaks the exam down domain by domain.

CAIGP sits on AICA's professional track, alongside CAAP and CAIP, and is built for practitioners who sit inside the governance function itself: risk teams, compliance officers, internal audit, data protection leads, and AI program managers who need to show, not just describe, how they control AI systems in production.

What Does the CAIGP Exam Actually Assess?

The CAIGP assessment format is an examination paired with an applied governance portfolio. The examination tests domain knowledge across all six competency areas. The portfolio component asks candidates to produce or demonstrate governance work product, such as policy documentation, risk assessments, or audit-ready evidence, rather than answer questions about them in the abstract.

This two-part structure exists because AI governance is a practiced discipline, not a body of facts to memorize. A governance professional who can define a risk tiering framework in an exam room but has never built one is only half-prepared for the job. AICA's approach forces both halves to show up before certification is granted.

Because AICA is a newly launched body, candidates should not expect a long institutional track record or a large alumni base to draw on for exam folklore. What candidates can rely on is the published domain structure itself, which is the most reliable guide to what the exam covers and how to study for it.

The Six CAIGP Competency Domains

CAIGP assesses six domains. Each one maps to a distinct part of what an AI governance function actually does day to day, from writing the policy through to handling the incident when something goes wrong. Treat each domain as a separate study block with its own reading list, its own practice artifacts, and its own review pass.

Domain 1: AI Policy Implementation

This domain tests whether a candidate can take an organization's AI principles and turn them into operating policy that people actually follow. That means translating high-level commitments (fairness, transparency, human oversight) into specific, enforceable procedures: approval gates before a model goes into production, defined roles and responsibilities, escalation paths, and policy review cycles.

Policy implementation is where most governance programs fail in practice. A policy that exists only as a PDF nobody reads is not implementation. The exam and portfolio both look for evidence that a candidate understands the difference between writing a policy and operationalizing one.

Study prep for this domain:

  • Practice drafting a policy statement and then breaking it into three to five enforceable procedures with named owners.
  • Study how policy exceptions and waivers should be documented and time-bound, not left open-ended.
  • Review how policy changes get communicated and adopted across a distributed organization, not just approved by committee.
  • Build familiarity with common policy structures: acceptable use, model approval, third-party AI vendor vetting, and data use in AI training.

Domain 2: Model Risk Documentation and Impact Assessments

This domain covers the discipline of documenting what a model does, what could go wrong, and how serious that would be, before and during deployment. It includes model cards, data lineage records, and formal AI impact assessments that weigh potential harms against intended benefits.

A candidate needs to be able to structure a risk assessment that a non-technical reviewer, such as a board member or regulator, can actually follow. That means clear articulation of intended use, known limitations, affected populations, and mitigation steps, not just a technical accuracy score.

Study prep for this domain:

  • Practice writing a model card for a hypothetical system: purpose, training data description, known limitations, and intended versus prohibited uses.
  • Learn the standard components of an AI impact assessment: risk identification, likelihood and severity scoring, affected stakeholder analysis, and mitigation planning.
  • Study how risk documentation should differ for a low-risk internal tool versus a high-risk system affecting consumer decisions.
  • Review how documentation needs to be version-controlled and updated as a model is retrained or repurposed.

Domain 3: Regulatory Mapping and Compliance Workflows

This domain tests the ability to identify which laws, standards, and frameworks apply to a given AI system and to build a workflow that keeps compliance current as regulation evolves. This is not about memorizing every clause of every AI law globally. It is about building a repeatable process for mapping a system's characteristics (sector, geography, risk level, data types) to the obligations that follow from them.

Because AI regulation is fragmented and moving quickly across jurisdictions, the exam favors candidates who understand the mapping method over those who have memorized a single regulation that may already be outdated by the time they sit the exam.

Study prep for this domain:

  • Practice building a regulatory mapping matrix: system characteristic in one column, applicable obligation in the next, evidence source in the third.
  • Study the general categories most AI-specific regulation falls into: risk-tiering requirements, transparency and disclosure duties, human oversight mandates, and data protection overlaps.
  • Learn how to structure a compliance workflow with clear triggers for reassessment, such as a model update, a new market launch, or a regulatory change.
  • Review how cross-functional ownership works between legal, compliance, and the AI governance function so mapping does not stall in handoffs.

Domain 4: AI Inventory and Lifecycle Controls

This domain covers the foundational discipline of knowing what AI systems an organization actually has, where they came from, who owns them, and what stage of their lifecycle they are in. Without an accurate inventory, none of the other domains can function: a policy cannot be enforced on a system nobody knows exists, and an incident cannot be traced to its source without a documented lineage.

Lifecycle controls extend the inventory into an operating discipline covering intake, approval, monitoring, retraining, and retirement. The exam tests whether a candidate can design controls that catch systems at each of these stages, including shadow AI tools adopted outside formal channels.

Study prep for this domain:

  • Practice designing an AI system intake form that captures owner, purpose, data sources, and risk tier at the point of adoption.
  • Study the stages of a typical AI lifecycle: development, validation, deployment, monitoring, retraining, and decommissioning, and what control checkpoint belongs at each.
  • Learn methods for discovering unregistered or shadow AI tools already in use across business units.
  • Review how inventory records should link forward to risk assessments and policy classifications, not sit as a standalone spreadsheet.

Domain 5: Audit Preparation and Evidence Management

This domain tests whether a candidate can keep governance evidence in a state that survives external scrutiny, whether that scrutiny comes from an internal audit function, a regulator, or a customer due diligence review. Evidence management means version control, retention schedules, access logs, and the ability to reconstruct a decision trail on demand.

Audit readiness is not a task performed right before an audit. It is a standing discipline of keeping documentation current so that when an audit request lands, the evidence already exists and only needs to be assembled and presented.

Study prep for this domain:

  • Practice building an evidence index that maps each policy or control back to the specific document that proves it was followed.
  • Study common audit request patterns: sampling of decisions, testing of control effectiveness, and interview preparation for governance staff.
  • Learn retention and version control practices so evidence remains defensible months or years after a decision was made.
  • Review how to close audit findings with corrective action plans that include owners and deadlines, not just narrative responses.

Domain 6: Incident Response for AI Systems

This domain covers how a governance function detects, contains, investigates, and reports on AI system failures, whether that is a biased output, a data leak, a model behaving outside its intended scope, or a safety-relevant malfunction. AI incident response borrows structure from traditional security incident response but has to account for failure modes that are harder to detect, such as gradual model drift or subtle discriminatory outcomes.

The exam tests whether a candidate can design a response process with clear severity tiers, defined roles, and reporting obligations to both internal leadership and, where required, external regulators or affected individuals.

Study prep for this domain:

  • Practice drafting an AI incident severity matrix with clear thresholds for escalation.
  • Study the difference between detecting an acute failure (a system produces an obviously wrong or harmful output) and a gradual one (performance degrades slowly across a subgroup).
  • Learn what a post-incident review should document: root cause, containment steps taken, and control changes made to prevent recurrence.
  • Review notification obligations, including when affected individuals or regulators may need to be informed, and how those timelines interact with internal investigation timelines.

How Should Candidates Structure Their Study Time?

Because the assessment pairs an examination with an applied portfolio, study time should split roughly in two. Domain knowledge review builds the vocabulary and frameworks needed for the exam. Portfolio practice builds the muscle of actually producing the documents a governance professional is expected to create on the job.

A practical approach is to work through each of the six domains in sequence, producing one artifact per domain, a draft policy, a model risk assessment, a regulatory mapping matrix, an inventory intake form, an evidence index, and an incident severity matrix, before moving to full-length review. Candidates who arrive with only exam-style recall and no drafted artifacts are underprepared for the portfolio half of the assessment.

Candidates should also treat the six domains as interconnected rather than isolated. A regulatory mapping feeds the risk assessment. A risk assessment sets the severity tiers used in incident response. An inventory record is what makes an audit evidence trail possible. Studying the domains in isolation misses how they function together inside a real governance program.

Key Takeaways

  • CAIGP assessment combines an examination with an applied governance portfolio, so preparation must include producing real documents, not just reviewing concepts.
  • The six domains, policy implementation, risk documentation, regulatory mapping, inventory and lifecycle controls, audit preparation, and incident response, mirror the actual workflow of an AI governance function.
  • Preparation is strongest when candidates draft one practice artifact per domain rather than relying on recall alone.
  • The domains are interconnected: inventory feeds risk assessment, risk assessment feeds incident severity tiers, and all three feed audit evidence.
  • Because AICA is newly established, candidates should rely on the published domain structure and assessment format rather than exam folklore or informal test-taker accounts.

For the full domain descriptions, eligibility requirements, and how to register, see AICA's CAIGP certification page.