The AIGP blueprint, laid over an open body of knowledge.
Where this site teaches each of the 58 performance indicators of the public AIGP Body of Knowledge v2.1: the section to read first, the artefact it leads to, and whether the indicator is taught or partly taught.
How to read the map
The IAPP publishes the AIGP Body of Knowledge and Exam Blueprint as a public PDF. Version 2.1 took effect on 2 Feb 2026 and replaced version 2.0.1. It sets out four domains and 13 competencies, gives each a minimum and maximum number of exam questions, and lists the performance indicators under each competency1. The four domain ranges add up to 77 to 93 questions (16 + 19 + 21 + 21 and 20 + 23 + 25 + 25).
Each indicator here has a positional id: II.C.5 is the fifth indicator of
competency II.C, in the blueprint's order. For each one the map gives the section to
study first, then the artefact that section leads to (a pattern, a template, a tool, a
glossary term or a reference page), and a status on the house criterion:
- Taught
- A section lets a reader learn the indicator and leads to an artefact they can reuse.
- Partly taught
- The site covers the topic, but thinly or without an artefact of its own; the row says what is missing.
There is no overall score, on purpose. Coverage of a blueprint says where to read; it does not say whether anyone can run the controls, which is the argument of chapter 06 about certifications as a proxy for capability. The map was checked against the site and the blueprint on 24 Sep 2026; the blueprint is reviewed every year, so read it as of that date.
The heatmap
The whole map at a glance, generated from the same data as the tables below. The tables are its text form: every cell of the heatmap is one row there.
Text description
Each bar is as wide as the midpoint of its competency's question range; for example, 4–6 questions gives a bar 5 questions wide ((4 + 6) / 2). Domain I, Foundations of AI governance (16–20 questions): I.A, 4–6 questions: four indicators, each taught; I.B, 5–7 questions: five indicators, each taught; I.C, 6–8 questions: three indicators, each taught. Domain II, Laws, standards and frameworks (19–23 questions): II.A, 4–6 questions: four indicators, each taught; II.B, 4–6 questions: four indicators, II.B.3 partly taught, the rest taught; II.C, 6–8 questions: six indicators, II.C.5 partly taught, the rest taught; II.D, 3–5 questions: three indicators, each taught. Domain III, Governing AI development (21–25 questions): III.A, 6–8 questions: five indicators, each taught; III.B, 6–8 questions: five indicators, each taught; III.C, 8–10 questions: six indicators, each taught. Domain IV, Governing AI deployment and use (21–25 questions): IV.A, 6–8 questions: three indicators, each taught; IV.B, 5–7 questions: three indicators, IV.B.3 partly taught, the rest taught; IV.C, 9–11 questions: seven indicators, each taught.
Study paths, one per domain
Each path is the first section of every indicator in the domain, in the blueprint's order, with a section that serves two indicators listed once. Read a section, then open the artefact its row links to below.
Indicative, not legal advice and not a conformity claim. Nothing you enter leaves your browser.
Without JavaScript each path is a plain reading list. With it, you can tick sections off; the ticks are kept in this browser only, and nothing is sent anywhere.
Tick a section when you have read it. Your ticks are kept in this browser's storage only; nothing is sent anywhere, and clearing your browser data removes them.
This browser is not keeping storage for this page (a private window, or blocked site data), so your ticks will not survive a reload.
Domain I: Foundations of AI governance
0 of 12 sections read
- Ch. 11 · Four definitions, compared For I.A.1
- Ch. 13 · Internal and external risk sources For I.A.2
- Ch. 11 · Eight characteristics that break classic IT governance For I.A.3
- Ch. 11 · Responsible-AI principle sets, engineered For I.A.4
- Ch. 12 · The stakeholder map For I.B.1
- Ch. 12 · The committee decides, the gates enforce For I.B.2
- Ch. 12 · AI literacy as code For I.B.3
- Ch. 13 · Proportionate governance: tailoring the loop For I.B.4
- Ch. 18 · Who you are in the value chain For I.B.5
- Ch. 12 · Policies across the lifecycle For I.C.1
- Ch. 12 · Updating the policies you already have For I.C.2
- Ch. 12 · Third-party AI policy For I.C.3
Domain II: Laws, standards and frameworks
0 of 17 sections read
- Ch. 19 · Principles applied to AI For II.A.1
- Ch. 19 · Minimisation, privacy by design and PETs For II.A.2
- Ch. 19 · Controller duties across the AI supply chain For II.A.3
- Ch. 19 · Special categories, inferred data and biometrics For II.A.4
- Ch. 20 · Intellectual property For II.B.1
- Ch. 20 · Non-discrimination For II.B.2
- Ch. 20 · Consumer protection For II.B.3
- Ch. 20 · Product liability For II.B.4
- Ch. 18 · The risk ladder For II.C.1
- Ch. 18 · High-risk requirements (Articles 8 to 15) For II.C.2
- Ch. 04 · Designing human oversight (Article 14) For II.C.3
- Ch. 18 · General-purpose AI models For II.C.4
- Ch. 18 · Governance and enforcement For II.C.5
- Ch. 18 · The EU operator roles For II.C.6
- Ch. 22 · OECD AI Principles For II.D.1
- Ch. 22 · NIST AI RMF 1.0 in depth For II.D.2
- Ch. 22 · The ISO/IEC family For II.D.3
Domain III: Governing AI development
0 of 16 sections read
- Ch. 14 · The use-case record For III.A.1
- Ch. 14 · Impact assessments compared For III.A.2
- Ch. 14 · Design review For III.A.3
- Ch. 13 · Assessing risk: the likelihood-by-severity matrix For III.A.4
- Ch. 14 · The technical file For III.A.5
- Ch. 14 · Data for training and testing For III.B.1
- Ch. 14 · Provenance versus lineage For III.B.2
- Ch. 14 · Testing and validation For III.B.3
- Ch. 14 · What goes wrong in training and testing For III.B.4
- Ch. 14 · Reproducibility and linked versioning For III.B.5
- Ch. 14 · Release readiness and conformity For III.C.1
- Ch. 15 · Maintenance calendar and retraining governance For III.C.2
- Ch. 15 · Periodic assurance For III.C.3
- Ch. 17 · Incident, hazard, issue and serious incident For III.C.4
- Ch. 17 · Root-cause analysis For III.C.5
- Ch. 14 · Public disclosures For III.C.6
Domain IV: Governing AI deployment and use
0 of 13 sections read
- Ch. 15 · The deployment decision For IV.A.1
- Ch. 15 · Model type changes the control set For IV.A.2
- Ch. 15 · Model types and deployment options For IV.A.3
- Ch. 18 · Fundamental rights impact assessment (Article 27) For IV.B.1
- Ch. 15 · Vendor contracts and licence terms For IV.B.2
- Ch. 15 · Build, buy or adapt For IV.B.3
- Ch. 15 · Policies at go-live For IV.C.1
- Ch. 15 · Operating the system For IV.C.2
- Ch. 15 · An audit programme, not an audit For IV.C.3
- Ch. 17 · Deployer duties: inform the provider, suspend use For IV.C.4
- Ch. 15 · Secondary use and downstream harm For IV.C.5
- Ch. 15 · External communications For IV.C.6
- Ch. 15 · Deactivation, degradation, localisation and retirement For IV.C.7
Domain I: Foundations of AI governance
16–20 exam questions in the blueprint1. Mostly taught in chapters 03, 11, 12, 13, 18.
I.A What AI is and why it needs governing 4–6 questions
| Indicator | Where this site teaches it | Status |
|---|---|---|
| I.A.1 Tell the main definitions of AI apart and classify kinds of AI. | Taught | |
| I.A.2 Name the harms AI can do to people, groups, organisations, society. | Taught | |
| I.A.3 Explain which traits of AI defeat classic IT governance. | Taught | |
| I.A.4 Turn widely shared responsible-AI principles into working controls. | Taught |
I.B Organisational expectations for AI governance 5–7 questions
| Indicator | Where this site teaches it | Status |
|---|---|---|
| I.B.1 Assign governance roles and responsibilities to every stakeholder. | Taught | |
| I.B.2 Make the governance programme cross-functional by design. | Taught | |
| I.B.3 Give each audience role-based AI literacy training, with records. | Taught | |
| I.B.4 Fit the programme to size, maturity, sector and risk appetite. | Taught | |
| I.B.5 Separate developer, provider, deployer and user duties. | Taught |
I.C Policies across the AI lifecycle 6–8 questions
| Indicator | Where this site teaches it | Status |
|---|---|---|
| I.C.1 Set policies that assign oversight at each lifecycle stage. | Taught | |
| I.C.2 Revisit privacy, security, data and IP policies for AI. | Taught | |
| I.C.3 Control third-party AI through policy, due diligence and contracts. | Taught |
Domain II: Laws, standards and frameworks
19–23 exam questions in the blueprint1. Mostly taught in chapters 08, 18, 19, 20, 21, 22.
II.A Privacy and data-protection law applied to AI 4–6 questions
| Indicator | Where this site teaches it | Status |
|---|---|---|
| II.A.1 Ground AI processing in a lawful basis, notice, choice and purpose. | Taught | |
| II.A.2 Minimise data and build privacy into AI by design. | Taught | |
| II.A.3 Carry controller duties, from DPIAs to rights and breaches, into AI. | Taught | |
| II.A.4 Handle special-category data, biometrics included, in AI systems. | Taught |
II.B Other existing law applied to AI 4–6 questions
| Indicator | Where this site teaches it | Status |
|---|---|---|
| II.B.1 See where copyright and other IP law limit AI training. | Taught | |
| II.B.2 Test AI decisions against non-discrimination law in regulated sectors. | Taught | |
| II.B.3 Keep AI claims and practices within consumer-protection law. | Partly taught The claims register is specified in prose; the gate that would enforce it is proposed in chapter 20, not yet a catalogued pattern or template. | |
| II.B.4 Read AI failures through product-liability defect theories. | Taught |
II.C AI-specific law 6–8 questions
| Indicator | Where this site teaches it | Status |
|---|---|---|
| II.C.1 Place an AI system on a risk ladder and justify it. | Taught | |
| II.C.2 Know the core high-risk duties, from risk management to records. | Taught | |
| II.C.3 Know the oversight, transparency, notice and quality-management duties. | Taught | |
| II.C.4 Know the separate duties that apply to general-purpose AI models. | Taught | |
| II.C.5 Know who enforces AI law and what penalties apply. | Partly taught Taught as knowledge in chapters 18 and 21; no artefact records a system's enforcement exposure beyond the dated obligation register. | |
| II.C.6 Tell apart provider, deployer, importer and distributor duties. | Taught |
II.D Standards and frameworks 3–5 questions
| Indicator | Where this site teaches it | Status |
|---|---|---|
| II.D.1 Use the OECD AI principles and classification framework. | Taught | |
| II.D.2 Work with the NIST AI RMF core and its Playbook. | Taught | |
| II.D.3 Know what ISO/IEC 22989, 42001 and 42005 each cover. | Taught |
Domain III: Governing AI development
21–25 exam questions in the blueprint1. Mostly taught in chapters 13, 14, 16, 17.
III.A Design and build 6–8 questions
| Indicator | Where this site teaches it | Status |
|---|---|---|
| III.A.1 Record the business problem and use case before building. | Taught | |
| III.A.2 Carry out, or check another team's, assessment of the system's impacts. | Taught | |
| III.A.3 Apply policy and ethics in design review, oversight included. | Taught | |
| III.A.4 Find and treat design-stage risks with matrix, hierarchy, pilots. | Taught | |
| III.A.5 Keep a traceable record of design and build decisions. | Taught |
III.B Data for training and testing 6–8 questions
| Indicator | Where this site teaches it | Status |
|---|---|---|
| III.B.1 Check the right to use data and its fitness for purpose. | Taught | |
| III.B.2 Record where data came from and how it moved. | Taught | |
| III.B.3 Plan and run the full range of tests before release. | Taught | |
| III.B.4 Catch and handle problems that surface in training and testing. | Taught | |
| III.B.5 Document training and testing so results can be reproduced. | Taught |
III.C Release, monitoring and maintenance 8–10 questions
| Indicator | Where this site teaches it | Status |
|---|---|---|
| III.C.1 Decide release readiness with cards and conformity steps done. | Taught | |
| III.C.2 Monitor the system and schedule maintenance and retraining. | Taught | |
| III.C.3 Audit, red-team and threat-model the system on a schedule. | Taught | |
| III.C.4 After release, log and resolve incidents, open issues and risks. | Taught | |
| III.C.5 Work across teams to find why AI incidents happen. | Taught | |
| III.C.6 Publish the documentation transparency duties require, instructions included. | Taught |
Domain IV: Governing AI deployment and use
21–25 exam questions in the blueprint1. Mostly taught in chapters 15, 17, 18, 23.
IV.A The decision to deploy 6–8 questions
| Indicator | Where this site teaches it | Status |
|---|---|---|
| IV.A.1 Frame the deployment by purpose, performance, data, ethics, readiness. | Taught | |
| IV.A.2 Compare model types: predictive or generative, open or closed, size, modality. | Taught | |
| IV.A.3 Compare where a model runs and how it is adapted. | Taught |
IV.B Assessing the selected system 5–7 questions
| Indicator | Where this site teaches it | Status |
|---|---|---|
| IV.B.1 Assess the impact of the chosen system before go-live. | Taught | |
| IV.B.2 Review vendor and licence terms for AI-specific risk. | Taught | |
| IV.B.3 Weigh the burdens and gains of running your own model. | Partly taught A short subsection in chapter 15; no record captures the build, buy or adapt choice beyond the role assessment in the deployment decision record. |
IV.C Deployment and use 9–11 questions
| Indicator | Where this site teaches it | Status |
|---|---|---|
| IV.C.1 Apply policy at go-live: data, risk, issues, user training. | Taught | |
| IV.C.2 Monitor the deployed model and system; plan maintenance. | Taught | |
| IV.C.3 Assure the deployed system periodically: audits, red teams, threat models. | Taught | |
| IV.C.4 Keep incident and issue records, the risk log and monitoring plan. | Taught | |
| IV.C.5 Anticipate secondary uses and downstream harm, then contain them. | Taught | |
| IV.C.6 Plan how and when to communicate outside the organisation. | Taught | |
| IV.C.7 Be able to deactivate, degrade or localise a system on a trigger. | Taught |
What this map is not
- Not exam preparation. It does not reproduce, predict or rehearse exam questions, and it does not say what the exam weighs within a competency. The blueprint is the only statement of what is examined.
- Not affiliated. AIGP is a registered trademark of the IAPP. This site is not affiliated with or endorsed by the IAPP, and the IAPP has not reviewed this map.
- Not a claim of competence. A reader who has read every section has read every section. The body of knowledge measures work by the evidence a control leaves behind, and so does the maturity self-check.
- Not legal advice. The map points at chapters that cite the law; it does not tell anyone which obligations apply to them. Mappings are illustrative, not a claim of conformity.
Found a wrong anchor, a better section or an indicator we mark taught that you think is not? Corrections are welcome.
Sources
- [1] AIGP Body of Knowledge and Exam Blueprint, version 2.1 (four domains and 13 competencies with the minimum and maximum number of exam questions for each, and the performance indicators under each competency; approved 9 Sep 2025, effective 2 Feb 2026, supersedes 2.0.1; reviewed every year, with changes announced at least 90 days ahead). IAPP. 2026-02-02. https://prod.iapp.org/media/pdf/certification/AIGP_Cert_BOK_2025_FINAL_v2.1.0.pdf (verified: primary)