On this page

Certifications, neutrally

Who owns each AI governance certification, what the owner says it assesses, and how this open body of knowledge relates to it: facts checked on 24 Sep 2026, no ranking.

How to read this page

Five personal certifications bear on AI governance work. This page says who owns each scheme, what the owner says it assesses, and how this body of knowledge relates to it. Every fact comes from the scheme owner's own material, a standards body or EUR-Lex, read on 24 Sep 2026, and carries a numbered source. The page does not rank the schemes, recommend one, or offer study material. Schemes change (the AIGP blueprint, for one, is reviewed every year1), so check the owner's page before you rely on a detail. For the field these schemes assess, see AI governance, defined.

AIGP is a registered trademark of the IAPP. AAISM and AAIA are trademarks of ISACA. This site is not affiliated with or endorsed by the IAPP, ISACA, ISO, IEC or any certification body named here.

Two kinds of certificate

A certificate of a person says that someone passed an assessment set by a scheme owner. A certificate of a management system says that a certification body audited an organisation's AI management system (AIMS) against ISO/IEC 420016. The two are easy to confuse, because some personal schemes carry the standard's name.

ISO does not perform certification or issue certificates; external certification bodies do3. Bodies that certify persons can work to ISO/IEC 17024, whose 2026 edition replaced the 2012 one4; bodies that audit and certify an AIMS against ISO/IEC 42001 work to ISO/IEC 42006:2025, which builds on ISO/IEC 17021-15. What an organisation's 42001 certificate proves, and what it does not, is set out in chapter 07: it evidences a management system and confers no presumption of conformity with the EU AI Act.

At a glance

Five personal certifications: owner, what the owner says each assesses, and the closest part of this body of knowledge
Scheme Owner What the owner says it assesses Closest part of this body of knowledge
AIGP IAPP Knowledge across four domains: foundations of AI governance; laws, standards and frameworks; governing development; governing deployment and use1 All four parts; indicator by indicator in the AIGP coverage map
ISO/IEC 42001 Lead Implementer The issuing body (for example, PECB) Planning, implementing and improving an AIMS based on ISO/IEC 42001, after a course and an exam7 Chapter 12 and the management-system trio in chapter 22
ISO/IEC 42001 Lead Auditor The issuing body (for example, PECB) Auditing organisations against ISO/IEC 42001, after a course and an exam8 What internal audit tests and an audit programme
AAISM ISACA AI security management: governance and program management, risk management, and AI technologies and controls9 Layers 03 and 04 of the stack and governing agents
AAIA ISACA AI audit: governance and risk, AI operations, and auditing tools and techniques10 Layer 05 of the stack and incidents

Mappings are illustrative, not a claim of conformity or of equivalence: reading a chapter does not earn a credential, and a credential does not cover the chapter.

AIGP (IAPP)

The IAPP's Certified AI Governance Professional is examined against the AIGP Body of Knowledge and Exam Blueprint. Version 2.1 was approved on 9 Sep 2025, took effect on 2 Feb 2026 and replaced version 2.0.1. It has four domains, each with a minimum and maximum number of exam questions (Domain I, 16–20; Domain II, 19–23; Domain III, 21–25; Domain IV, 21–25), and 13 competencies; by our count it lists 58 performance indicators. It says its questions mostly sit at the remember and understand, and apply and analyse, levels of Bloom's taxonomy, and names the EU AI Act and the South Korean AI Basic Law among the AI laws it covers1.

The IAPP's candidate handbook says its exams are multiple choice, with one or more correct answers and some questions set on a scenario; that its core exams are scored from 100 to 500, with 300 to pass; that about 10% to 15% of exam content changes each year, with changes to a body of knowledge announced at least 90 days ahead; and that a certification is in good standing only with IAPP membership or a maintenance fee. It lists CIPP/E, CIPP/US, CIPM and CIPT as accredited by ANAB under ISO/IEC 17024:2012, and says AIGP is not accredited by ANAB2.

How this body of knowledge relates. The two overlap heavily in topic and differ in purpose. The blueprint states what is examined; this book is built around what a governance function runs and the evidence it leaves, so its chapters end in artefacts: a registry entry, a gate, a template, a record. The AIGP coverage map lays the blueprint's indicators over the chapters, one by one, and says where the book is only partly there. It is a coverage map of an open body of knowledge, not exam preparation.

ISO/IEC 42001 Lead Implementer and Lead Auditor

These titles name personal certificates, not the certification of an organisation. Because ISO issues no certificates3, each scheme belongs to the body that runs it, with its own course, exam and conditions. One example: PECB offers an ISO/IEC 42001 Lead Implementer credential and an ISO/IEC 42001 Lead Auditor credential, each after a training course and an exam, and describes the second as expertise in auditing organisations against ISO/IEC 4200178. It is cited as an example of the category, not an endorsement. Two credentials with the same title can differ, so compare the scheme documents, not the name.

How this body of knowledge relates. The standard itself is covered in chapter 22 (with 42005 and 42006) and chapter 08; the organisation that runs an AIMS, from the committee to management review, in chapter 12; and what a 42001 audit can and cannot see, in chapter 07. For the auditor's side, read what internal audit tests and an audit programme, not an audit; the Machine-Readable Evidence (OSCAL) pattern is how the evidence reaches an auditor as data.

AAISM (ISACA)

ISACA's Advanced in AI Security Management is open to candidates who hold an active CISM or CISSP. ISACA lists three practice areas: AI governance and program management, AI risk management, and AI technologies and controls. The exam is computer-based, at a test centre or remotely proctored9.

How this body of knowledge relates. AI security engineering is this discipline's sibling, not the discipline itself (see the disambiguation cluster). The overlap sits in Layers 03 and 04 of the stack, in governing agents (identity, tool permissions, runtime guardrails, the kill switch) and in patterns such as the Adversarial Red-Team Suite and the Runtime Guardrail.

AAIA (ISACA)

ISACA's Advanced in AI Audit is open to candidates who hold an active CISA or a qualified designation from a published list, which includes CIA and several national CPA credentials. ISACA lists three domains: AI governance and risk, AI operations, and AI auditing tools and techniques10.

How this body of knowledge relates. An auditor reads what Layer 05 of the stack produces: continuous assurance telemetry, machine-readable evidence and the records in the templates and schemas. The three lines applied to AI places internal audit in the programme, and CAPA shows how a failure becomes a corrective and preventive action, a regression eval and a risk register change.

What a certificate shows, and what it does not

A personal certificate shows that its holder passed an assessment of knowledge at a point in time, against a blueprint the owner revises. It does not show that an eval gate blocks a build, that the registry is true on any Tuesday, or that evidence is machine-readable. That is the argument of chapter 06: descriptions list certifications as if a certificate produced a control. Ask for the workflow first, then the certificate if it helps.

No certificate is a legal requirement for AI literacy under the EU AI Act. Article 4 asks providers and deployers to take measures to support the development of AI literacy of their staff and others dealing with AI systems on their behalf, without requiring them to guarantee any specific level for any individual11, and the Commission's questions and answers say no certificate is needed and an internal record of trainings will do12. How to run that record as code is in chapter 12.

Sources

  1. [1] AIGP Body of Knowledge and Exam Blueprint, version 2.1 (Certified AI Governance Professional; four domains with minimum and maximum exam questions; competencies and performance indicators; questions mostly at the remember/understand and apply/analyse levels of Bloom's taxonomy; the EU AI Act and the South Korean AI Basic Law named as examples; approved 9 Sep 2025, effective 2 Feb 2026, supersedes 2.0.1). IAPP. 2026-02-02. https://prod.iapp.org/media/pdf/certification/AIGP_Cert_BOK_2025_FINAL_v2.1.0.pdf (verified: primary)
  2. [2] IAPP candidate handbook: procedures and policies, version 5.3.2 (CIPP/E, CIPP/US, CIPM and CIPT accredited by ANAB under ISO/IEC 17024:2012, AIGP, CDPO, CIPP/A and CIPP/C not; multiple-choice questions with one or more correct answers, some on a scenario; core exams scored from 100 to 500 with 300 to pass; about 10% to 15% of exam content changed each year, body-of-knowledge changes announced at least 90 days ahead; IAPP membership or a maintenance fee required for a certification in good standing; effective 1 Jun 2026). IAPP. 2026-06-01. https://iapp.org/certify/candidate-handbook/ (verified: primary)
  3. [3] Certification (ISO does not perform certification or issue certificates; certification is performed by external certification bodies; accreditation is not compulsory). ISO. 2026-09-24. https://www.iso.org/certification.html (verified: primary)
  4. [4] ISO/IEC 17024:2026, Conformity assessment: general requirements for bodies operating certification of persons (edition 3, published 2026-03, replacing ISO/IEC 17024:2012). ISO/IEC. 2026-03. https://www.iso.org/standard/17024 (verified: primary)
  5. [5] ISO/IEC 42006:2025, Requirements for AIMS audit and certification bodies (builds on ISO/IEC 17021-1). ISO/IEC. 2025-07. https://www.iso.org/standard/44546.html (verified: primary)
  6. [6] ISO/IEC 42001:2023, AI management systems (requirements for establishing, implementing, maintaining and continually improving an AIMS). ISO/IEC. 2023-12. https://www.iso.org/standard/81230.html (verified: primary)
  7. [7] ISO/IEC 42001 Lead Implementer (a training course on planning, implementing, managing, monitoring, maintaining and continually improving an AIMS based on ISO/IEC 42001, then an exam, then an application for the "PECB Certified ISO/IEC 42001 Lead Implementer" credential; cited as one example of a scheme, not an endorsement). PECB. 2026-09-24. https://pecb.com/en/education-and-certification-for-individuals/iso-iec-42001/iso-iec-42001-lead-implementer (verified: primary)
  8. [8] ISO/IEC 42001 Lead Auditor (training course, then an exam, then an application for the "PECB Certified ISO/IEC 42001 Lead Auditor" credential, described as expertise in auditing organisations against ISO/IEC 42001; cited as one example of a scheme, not an endorsement). PECB. 2026-09-24. https://pecb.com/en/education-and-certification-for-individuals/iso-iec-42001/iso-iec-42001-lead-auditor (verified: primary)
  9. [9] ISACA Advanced in AI Security Management (AAISM) (candidates must hold an active CISM or CISSP; three practice areas: AI governance and program management, AI risk management, AI technologies and controls; computer-based exam at a test centre or remotely proctored). ISACA. 2026-09-24. https://www.isaca.org/credentialing/aaism (verified: primary)
  10. [10] Advanced in AI Audit (AAIA) (candidates must hold an active CISA or a qualified designation from a published list (including CIA and several national CPA credentials); three domains: AI governance and risk, AI operations, AI auditing tools and techniques). ISACA. 2026-09-24. https://www.isaca.org/credentialing/aaia (verified: primary)
  11. [11] Regulation (EU) 2024/1689 (Artificial Intelligence Act), Art. 4, consolidated text as amended by Regulation (EU) 2026/1744 (providers and deployers take measures to support the development of AI literacy of their staff and others dealing with AI systems on their behalf; the obligation does not require them to guarantee any specific level of AI literacy of any individual). Publications Office of the EU (EUR-Lex). 2026-07-27. https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_4 (verified: primary)
  12. [12] AI Literacy: Questions & Answers (no specific or "sufficient" level mandated; no certificate needed; an internal record of trainings will do). European Commission. 2026-07-27. https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers (verified: primary)