The AIGP blueprint, laid over an open body of knowledge.

Where this site teaches each of the 58 performance indicators of the public AIGP Body of Knowledge v2.1: the section to read first, the artefact it leads to, and whether the indicator is taught or partly taught.

How to read the map

The IAPP publishes the AIGP Body of Knowledge and Exam Blueprint as a public PDF. Version 2.1 took effect on 2 Feb 2026 and replaced version 2.0.1. It sets out four domains and 13 competencies, gives each a minimum and maximum number of exam questions, and lists the performance indicators under each competency1. The four domain ranges add up to 77 to 93 questions (16 + 19 + 21 + 21 and 20 + 23 + 25 + 25).

Each indicator here has a positional id: II.C.5 is the fifth indicator of competency II.C, in the blueprint's order. For each one the map gives the section to study first, then the artefact that section leads to (a pattern, a template, a tool, a glossary term or a reference page), and a status on the house criterion:

Taught
A section lets a reader learn the indicator and leads to an artefact they can reuse.
Partly taught
The site covers the topic, but thinly or without an artefact of its own; the row says what is missing.

There is no overall score, on purpose. Coverage of a blueprint says where to read; it does not say whether anyone can run the controls, which is the argument of chapter 06 about certifications as a proxy for capability. The map was checked against the site and the blueprint on 24 Sep 2026; the blueprint is reviewed every year, so read it as of that date.

The heatmap

The whole map at a glance, generated from the same data as the tables below. The tables are its text form: every cell of the heatmap is one row there.

AIGP coverage heatmapHeatmap of the 58 AIGP performance indicators in 13 competencies, each cell marked taught or partly taught on this site.AIGP BoK v2.1 · 58 indicatorsOne cell per indicator, one bar per competencyExam questions (range midpoint)0246810I · Foundations of AI governance16–20II · Laws, standards and frameworks19–23III · Governing AI development21–25IV · Governing AI deployment and use21–25I.AI.BI.CII.AII.BII.CII.DIII.AIII.BIII.CIV.AIV.BIV.C4–65–76–84–64–66–83–56–86–88–106–85–79–111234123451231234123412345612312345123451234561231231234567TaughtPartly taughtSource: AIGP BoK v2.1, IAPP, 2026-02-02Coverage: this site · As of 2026-09-24
AIGP coverage heatmap One bar per competency, as wide as the midpoint of its exam question range, split into one cell per indicator: filled where this site teaches the indicator, dashed where it is only partly taught. Start from a dashed cell if you want to know where this body of knowledge is thin. Drawn from the coverage map on this page.
Text description

Each bar is as wide as the midpoint of its competency's question range; for example, 4–6 questions gives a bar 5 questions wide ((4 + 6) / 2). Domain I, Foundations of AI governance (16–20 questions): I.A, 4–6 questions: four indicators, each taught; I.B, 5–7 questions: five indicators, each taught; I.C, 6–8 questions: three indicators, each taught. Domain II, Laws, standards and frameworks (19–23 questions): II.A, 4–6 questions: four indicators, each taught; II.B, 4–6 questions: four indicators, II.B.3 partly taught, the rest taught; II.C, 6–8 questions: six indicators, II.C.5 partly taught, the rest taught; II.D, 3–5 questions: three indicators, each taught. Domain III, Governing AI development (21–25 questions): III.A, 6–8 questions: five indicators, each taught; III.B, 6–8 questions: five indicators, each taught; III.C, 8–10 questions: six indicators, each taught. Domain IV, Governing AI deployment and use (21–25 questions): IV.A, 6–8 questions: three indicators, each taught; IV.B, 5–7 questions: three indicators, IV.B.3 partly taught, the rest taught; IV.C, 9–11 questions: seven indicators, each taught.

Study paths, one per domain

Each path is the first section of every indicator in the domain, in the blueprint's order, with a section that serves two indicators listed once. Read a section, then open the artefact its row links to below.

Indicative, not legal advice and not a conformity claim. Nothing you enter leaves your browser.

Without JavaScript each path is a plain reading list. With it, you can tick sections off; the ticks are kept in this browser only, and nothing is sent anywhere.

Domain I: Foundations of AI governance

  1. Ch. 11 · Four definitions, compared For I.A.1
  2. Ch. 13 · Internal and external risk sources For I.A.2
  3. Ch. 11 · Eight characteristics that break classic IT governance For I.A.3
  4. Ch. 11 · Responsible-AI principle sets, engineered For I.A.4
  5. Ch. 12 · The stakeholder map For I.B.1
  6. Ch. 12 · The committee decides, the gates enforce For I.B.2
  7. Ch. 12 · AI literacy as code For I.B.3
  8. Ch. 13 · Proportionate governance: tailoring the loop For I.B.4
  9. Ch. 18 · Who you are in the value chain For I.B.5
  10. Ch. 12 · Policies across the lifecycle For I.C.1
  11. Ch. 12 · Updating the policies you already have For I.C.2
  12. Ch. 12 · Third-party AI policy For I.C.3

Domain II: Laws, standards and frameworks

  1. Ch. 19 · Principles applied to AI For II.A.1
  2. Ch. 19 · Minimisation, privacy by design and PETs For II.A.2
  3. Ch. 19 · Controller duties across the AI supply chain For II.A.3
  4. Ch. 19 · Special categories, inferred data and biometrics For II.A.4
  5. Ch. 20 · Intellectual property For II.B.1
  6. Ch. 20 · Non-discrimination For II.B.2
  7. Ch. 20 · Consumer protection For II.B.3
  8. Ch. 20 · Product liability For II.B.4
  9. Ch. 18 · The risk ladder For II.C.1
  10. Ch. 18 · High-risk requirements (Articles 8 to 15) For II.C.2
  11. Ch. 04 · Designing human oversight (Article 14) For II.C.3
  12. Ch. 18 · General-purpose AI models For II.C.4
  13. Ch. 18 · Governance and enforcement For II.C.5
  14. Ch. 18 · The EU operator roles For II.C.6
  15. Ch. 22 · OECD AI Principles For II.D.1
  16. Ch. 22 · NIST AI RMF 1.0 in depth For II.D.2
  17. Ch. 22 · The ISO/IEC family For II.D.3

Domain III: Governing AI development

  1. Ch. 14 · The use-case record For III.A.1
  2. Ch. 14 · Impact assessments compared For III.A.2
  3. Ch. 14 · Design review For III.A.3
  4. Ch. 13 · Assessing risk: the likelihood-by-severity matrix For III.A.4
  5. Ch. 14 · The technical file For III.A.5
  6. Ch. 14 · Data for training and testing For III.B.1
  7. Ch. 14 · Provenance versus lineage For III.B.2
  8. Ch. 14 · Testing and validation For III.B.3
  9. Ch. 14 · What goes wrong in training and testing For III.B.4
  10. Ch. 14 · Reproducibility and linked versioning For III.B.5
  11. Ch. 14 · Release readiness and conformity For III.C.1
  12. Ch. 15 · Maintenance calendar and retraining governance For III.C.2
  13. Ch. 15 · Periodic assurance For III.C.3
  14. Ch. 17 · Incident, hazard, issue and serious incident For III.C.4
  15. Ch. 17 · Root-cause analysis For III.C.5
  16. Ch. 14 · Public disclosures For III.C.6

Domain IV: Governing AI deployment and use

  1. Ch. 15 · The deployment decision For IV.A.1
  2. Ch. 15 · Model type changes the control set For IV.A.2
  3. Ch. 15 · Model types and deployment options For IV.A.3
  4. Ch. 18 · Fundamental rights impact assessment (Article 27) For IV.B.1
  5. Ch. 15 · Vendor contracts and licence terms For IV.B.2
  6. Ch. 15 · Build, buy or adapt For IV.B.3
  7. Ch. 15 · Policies at go-live For IV.C.1
  8. Ch. 15 · Operating the system For IV.C.2
  9. Ch. 15 · An audit programme, not an audit For IV.C.3
  10. Ch. 17 · Deployer duties: inform the provider, suspend use For IV.C.4
  11. Ch. 15 · Secondary use and downstream harm For IV.C.5
  12. Ch. 15 · External communications For IV.C.6
  13. Ch. 15 · Deactivation, degradation, localisation and retirement For IV.C.7

Domain I: Foundations of AI governance

16–20 exam questions in the blueprint1. Mostly taught in chapters 03, 11, 12, 13, 18.

I.A What AI is and why it needs governing 4–6 questions

Indicators of competency I.A, where this site teaches each one, and its status
Indicator Where this site teaches it Status
I.A.1 Tell the main definitions of AI apart and classify kinds of AI. Taught
I.A.2 Name the harms AI can do to people, groups, organisations, society. Taught
I.A.3 Explain which traits of AI defeat classic IT governance. Taught
I.A.4 Turn widely shared responsible-AI principles into working controls. Taught

I.B Organisational expectations for AI governance 5–7 questions

I.C Policies across the AI lifecycle 6–8 questions

Indicators of competency I.C, where this site teaches each one, and its status
Indicator Where this site teaches it Status
I.C.1 Set policies that assign oversight at each lifecycle stage. Taught
I.C.2 Revisit privacy, security, data and IP policies for AI. Taught
I.C.3 Control third-party AI through policy, due diligence and contracts. Taught

Domain II: Laws, standards and frameworks

19–23 exam questions in the blueprint1. Mostly taught in chapters 08, 18, 19, 20, 21, 22.

II.A Privacy and data-protection law applied to AI 4–6 questions

Indicators of competency II.A, where this site teaches each one, and its status
Indicator Where this site teaches it Status
II.A.1 Ground AI processing in a lawful basis, notice, choice and purpose. Taught
II.A.2 Minimise data and build privacy into AI by design. Taught
II.A.3 Carry controller duties, from DPIAs to rights and breaches, into AI. Taught
II.A.4 Handle special-category data, biometrics included, in AI systems. Taught

II.B Other existing law applied to AI 4–6 questions

Indicators of competency II.B, where this site teaches each one, and its status
Indicator Where this site teaches it Status
II.B.1 See where copyright and other IP law limit AI training. Taught
II.B.2 Test AI decisions against non-discrimination law in regulated sectors. Taught
II.B.3 Keep AI claims and practices within consumer-protection law. Partly taught

The claims register is specified in prose; the gate that would enforce it is proposed in chapter 20, not yet a catalogued pattern or template.

II.B.4 Read AI failures through product-liability defect theories. Taught

II.C AI-specific law 6–8 questions

Indicators of competency II.C, where this site teaches each one, and its status
Indicator Where this site teaches it Status
II.C.1 Place an AI system on a risk ladder and justify it. Taught
II.C.2 Know the core high-risk duties, from risk management to records. Taught
II.C.3 Know the oversight, transparency, notice and quality-management duties. Taught
II.C.4 Know the separate duties that apply to general-purpose AI models. Taught
II.C.5 Know who enforces AI law and what penalties apply. Partly taught

Taught as knowledge in chapters 18 and 21; no artefact records a system's enforcement exposure beyond the dated obligation register.

II.C.6 Tell apart provider, deployer, importer and distributor duties. Taught

II.D Standards and frameworks 3–5 questions

Indicators of competency II.D, where this site teaches each one, and its status
Indicator Where this site teaches it Status
II.D.1 Use the OECD AI principles and classification framework. Taught
II.D.2 Work with the NIST AI RMF core and its Playbook. Taught
II.D.3 Know what ISO/IEC 22989, 42001 and 42005 each cover. Taught

Domain III: Governing AI development

21–25 exam questions in the blueprint1. Mostly taught in chapters 13, 14, 16, 17.

III.A Design and build 6–8 questions

Indicators of competency III.A, where this site teaches each one, and its status
Indicator Where this site teaches it Status
III.A.1 Record the business problem and use case before building. Taught
III.A.2 Carry out, or check another team's, assessment of the system's impacts. Taught
III.A.3 Apply policy and ethics in design review, oversight included. Taught
III.A.4 Find and treat design-stage risks with matrix, hierarchy, pilots. Taught
III.A.5 Keep a traceable record of design and build decisions. Taught

III.B Data for training and testing 6–8 questions

Indicators of competency III.B, where this site teaches each one, and its status
Indicator Where this site teaches it Status
III.B.1 Check the right to use data and its fitness for purpose. Taught
III.B.2 Record where data came from and how it moved. Taught
III.B.3 Plan and run the full range of tests before release. Taught
III.B.4 Catch and handle problems that surface in training and testing. Taught
III.B.5 Document training and testing so results can be reproduced. Taught

III.C Release, monitoring and maintenance 8–10 questions

Indicators of competency III.C, where this site teaches each one, and its status
Indicator Where this site teaches it Status
III.C.1 Decide release readiness with cards and conformity steps done. Taught
III.C.2 Monitor the system and schedule maintenance and retraining. Taught
III.C.3 Audit, red-team and threat-model the system on a schedule. Taught
III.C.4 After release, log and resolve incidents, open issues and risks. Taught
III.C.5 Work across teams to find why AI incidents happen. Taught
III.C.6 Publish the documentation transparency duties require, instructions included. Taught

Domain IV: Governing AI deployment and use

21–25 exam questions in the blueprint1. Mostly taught in chapters 15, 17, 18, 23.

IV.A The decision to deploy 6–8 questions

Indicators of competency IV.A, where this site teaches each one, and its status
Indicator Where this site teaches it Status
IV.A.1 Frame the deployment by purpose, performance, data, ethics, readiness. Taught
IV.A.2 Compare model types: predictive or generative, open or closed, size, modality. Taught
IV.A.3 Compare where a model runs and how it is adapted. Taught

IV.B Assessing the selected system 5–7 questions

Indicators of competency IV.B, where this site teaches each one, and its status
Indicator Where this site teaches it Status
IV.B.1 Assess the impact of the chosen system before go-live. Taught
IV.B.2 Review vendor and licence terms for AI-specific risk. Taught
IV.B.3 Weigh the burdens and gains of running your own model. Partly taught

A short subsection in chapter 15; no record captures the build, buy or adapt choice beyond the role assessment in the deployment decision record.

IV.C Deployment and use 9–11 questions

Indicators of competency IV.C, where this site teaches each one, and its status
Indicator Where this site teaches it Status
IV.C.1 Apply policy at go-live: data, risk, issues, user training. Taught
IV.C.2 Monitor the deployed model and system; plan maintenance. Taught
IV.C.3 Assure the deployed system periodically: audits, red teams, threat models. Taught
IV.C.4 Keep incident and issue records, the risk log and monitoring plan. Taught
IV.C.5 Anticipate secondary uses and downstream harm, then contain them. Taught
IV.C.6 Plan how and when to communicate outside the organisation. Taught
IV.C.7 Be able to deactivate, degrade or localise a system on a trigger. Taught

What this map is not

  • Not exam preparation. It does not reproduce, predict or rehearse exam questions, and it does not say what the exam weighs within a competency. The blueprint is the only statement of what is examined.
  • Not affiliated. AIGP is a registered trademark of the IAPP. This site is not affiliated with or endorsed by the IAPP, and the IAPP has not reviewed this map.
  • Not a claim of competence. A reader who has read every section has read every section. The body of knowledge measures work by the evidence a control leaves behind, and so does the maturity self-check.
  • Not legal advice. The map points at chapters that cite the law; it does not tell anyone which obligations apply to them. Mappings are illustrative, not a claim of conformity.

Found a wrong anchor, a better section or an indicator we mark taught that you think is not? Corrections are welcome.

Sources

  1. [1] AIGP Body of Knowledge and Exam Blueprint, version 2.1 (four domains and 13 competencies with the minimum and maximum number of exam questions for each, and the performance indicators under each competency; approved 9 Sep 2025, effective 2 Feb 2026, supersedes 2.0.1; reviewed every year, with changes announced at least 90 days ahead). IAPP. 2026-02-02. https://prod.iapp.org/media/pdf/certification/AIGP_Cert_BOK_2025_FINAL_v2.1.0.pdf (verified: primary)