Free AIGP Exam Flashcards
Memorize 50 essential terms and definitions for the IAPP Artificial Intelligence Governance Professional (AIGP). See the term, recall the definition, then flip to check yourself.
Why AI needs governance beyond ordinary software
AI outputs are probabilistic, data-dependent, and harder to predict in edge cases than deterministic software, so errors, bias, drift, opacity, and misuse can surface after release. Governance adds structured oversight, monitoring, and accountability that ordinary software controls do not cover.
Filter by Topic
Jump to Card
About These AIGP Flashcards
These 50 flashcards are designed to help you memorize key terms and definitions for the IAPP Artificial Intelligence Governance Professional (AIGP). Each card shows a term on the front and its definition on the back—the classic flashcard format for vocabulary memorization. Use these alongside our practice questions to build both recall and comprehension.
Topics Covered
Complete Flashcard Reference
Review every term in this set. Open any term to reveal its definition.
Why AI needs governance beyond ordinary software
AI outputs are probabilistic, data-dependent, and harder to predict in edge cases than deterministic software, so errors, bias, drift, opacity, and misuse can surface after release. Governance adds structured oversight, monitoring, and accountability that ordinary software controls do not cover.
Opacity and scale as a governance trigger
When an AI system acts with low transparency and high speed or scale, mistakes or unfairness can propagate before humans notice. That combination is what most directly justifies human oversight, monitoring, and clear accountability paths.
Generative AI vs. classification model
A classification model assigns labels or scores to inputs, while a generative system produces new content such as text, code, audio, or images. The generative profile raises distinct governance risks around hallucination, IP, safety, and misuse that classifiers usually do not.
Agentic AI vs. retrieval-only chatbot
An agentic system can plan, call tools, and take chained actions, so a single error can propagate beyond one answer. That justifies stricter controls such as approvals, permissions, rate limits, logging, and kill-switches that a retrieval-only chatbot does not need.
Data dependency as a governance concern
AI behavior is shaped by the quality, relevance, and representativeness of training data, so poor, biased, stale, or unrepresentative data directly distorts outputs. Governance therefore treats data provenance, quality, permissions, and fitness for purpose as first-order controls, not afterthoughts.
Fairness as a measurable control
Fairness in AI governance is not aspirational language; it must be translated into measurable evaluation such as testing error rates across protected groups. Without subgroup testing, an organization cannot detect disparate impact or defend consequential decisions.
Accountability through named owners
Accountability requires identifying who is responsible for approvals, monitoring, incidents, and remediation at each lifecycle stage. Informal or vendor-delegated ownership creates ambiguity that makes governance difficult to enforce or improve.
Safety and reliability vs. marketing claims
Safety and reliability depend on explicit performance thresholds and testing under realistic failure conditions, not on demo impressions or marketing language. Governance turns those expectations into repeatable validation controls before and after release.
Human-centric AI governance
Human-centric governance keeps human rights, agency, and meaningful oversight central to design and deployment. It does not ban automation; it requires that automation remain aligned with human values and that review paths stay real, not ceremonial.
Explainability in consequential decisions
Explainability matters most when AI affects people in high-stakes ways, because the organization must understand, justify, challenge, and monitor how decisions are made. It also supports compliance analysis when outcomes are later questioned.
Deployer vs. provider in governance
A provider builds or markets an AI system, while a deployer puts it into use within its own operational context. Even when a vendor built the model, the deployer retains governance duties around use controls, monitoring, and downstream impact.
User as a governance role
In governance terms the user is whoever interacts with the system and shapes how outputs are actually used downstream. That is why governance must train users, set acceptable-use controls, and capture feedback, because user behavior, not just model behavior, determines real-world impact.
Importer and distributor roles
Modern AI laws often separate provider, deployer, importer, and distributor roles because each does different things in the supply chain. Governance must map real operational roles to those legal labels early instead of assuming the upstream vendor owns every obligation.
Cross-functional governance group
AI risk rarely stays inside one function, so isolated legal, technical, or business review misses tradeoffs. A standing cross-functional group with legal, privacy, security, product, technical, and business representation reduces blind spots and makes ownership clearer across the lifecycle.
Procurement as a governance control point
Procurement is often the gateway for third-party AI, so it shapes vendor diligence and contract terms before adoption. Governance breaks down if procurement signs AI deals without aligning on privacy, security, IP, testing, and audit obligations.
Intake and review before build or deploy
Lifecycle governance starts before development or deployment, not after launch. A formal intake and review requirement creates the control point where risk assessment, role assignment, and documentation happen while the decision can still be changed.
Lifecycle checkpoints
Checkpoints such as intake, testing approval, deployment approval, and monitoring review make governance operational by defining when approval, evidence, and escalation are required. They prevent material model or data changes from bypassing governance.
Acceptable-use policy for AI tools
Acceptable-use rules limit both the tools employees may use and the use cases they may apply them to, with explicit data-handling restrictions. Confidence or convenience is not a substitute for approval, human review, and data controls.
Incident-management procedure
An incident-management procedure predetermines how AI issues are detected, escalated, contained, communicated, and remediated. Predetermined steps make response predictable under pressure and help preserve evidence and meet legal obligations.
IP and copyright risk in AI training
Training a model on copyrighted books or proprietary internal documents without clear permission can raise copyright and intellectual-property issues. IP review applies to third-party content and to internal material that may carry usage or confidentiality restrictions.
Discrimination law and AI screening
When an AI tool disadvantages protected groups in employment, housing, credit, or insurance, discrimination law becomes a central governance concern. A vendor source does not remove the deployer's duty to examine downstream effects.
Consumer protection and misleading AI claims
Marketing an AI system as objective or unbiased when internal testing shows disparities can create unfair or deceptive practices risk. Governance must ensure external claims match actual system behavior and evidence.
Product liability for AI-enabled products
When an AI-enabled product causes injury or economic harm because it behaves unpredictably, product liability law is highly relevant. Governance must therefore address testing, warnings, and release readiness, not only contractual disclaimers.
Why existing policies must be re-reviewed for AI
AI can change how data is collected, transformed, generated, monitored, or shared, so older privacy and security policies may not cover new AI-specific risks. Governance supplements existing policies rather than replacing them.
EU AI Act risk tiers
The EU AI Act sorts AI uses into tiers such as prohibited (unacceptable), high-risk, limited-risk (transparency), and minimal-risk, each carrying different compliance consequences. Tier classification drives which controls, documentation, and approvals are required before deployment.
Prohibited practices under the EU AI Act
Some uses are banned outright because lawmakers view them as unacceptable, distinct from high-risk uses that are allowed with obligations. Governance must distinguish prohibited from high-risk categories because no amount of mitigation makes a prohibited use lawful.
Provider vs. deployer duties in AI-specific law
AI-specific laws often assign different duties to providers and deployers because each does different things in the lifecycle. Governance must map real operational roles to those legal labels instead of assuming one party owns every obligation.
Transparency obligations in AI-specific law
AI-specific transparency rules often require telling people when they interact with certain systems or when content is synthetic. Governance must connect those legal duties to operational disclosures and downstream user-facing language.
General-purpose AI models
General-purpose models sit upstream of many products and services, so lawmakers increasingly impose obligations tailored to their broad impact and downstream reuse. Governance must look beyond the immediate application and consider upstream model obligations.
Lawful basis before AI training
Before using personal data to train or fine-tune a model, an organization must identify a lawful basis that addresses whether the use is allowed and under what conditions. Accuracy, security, and vendor controls do not substitute for permission to process.
Purpose limitation in AI projects
Reusing data collected for one defined purpose, such as order updates, to train a marketing-optimization model is a materially different purpose. AI projects trigger purpose-limitation questions whenever existing data is repurposed without fresh legal support or transparency.
Data minimization for AI
Data minimization limits collection and use to what is relevant and necessary for the defined purpose. In AI governance, that means resisting hoarding data simply because it might help later experiments.
Privacy by design in AI
Privacy by design embeds privacy into requirements, architecture, workflows, controls, and records from the start rather than adding it late. For AI, it includes minimization, transparency, access controls, and ongoing rights handling across the lifecycle.
OECD AI Principles
The OECD AI Principles are a widely cited, non-binding set of high-level expectations for trustworthy AI, including accountability, human-centered values, and transparency. They shape how organizations frame responsible AI even where they are not directly binding.
NIST AI RMF four functions
The NIST AI Risk Management Framework is organized around four functions: Govern, Map, Measure, and Manage. Govern is cross-cutting and anchors organizational context, roles, and oversight, while Map, Measure, and Manage handle context-setting, analysis, and response.
NIST AI RMF Playbook
The Playbook translates RMF concepts into concrete practices that teams can adopt when building or improving an AI governance program. It is a practical companion to the framework, not a legal override or a certifiable compliance scheme.
ISO/IEC 42001
ISO/IEC 42001 is the first certifiable international management system standard for AI, structured in the same Plan-Do-Check-Act shape as ISO 27001 and ISO 9001. Unlike NIST AI RMF, it can be audited and certified by an accredited third party.
ISO/IEC 22989
ISO/IEC 22989 provides shared AI concepts and terminology, which helps different teams use the same words to mean the same things. Governance breaks down quickly when stakeholders confuse terms such as model, system, deployer, or provider.
Use-case definition before design
Before any design work begins, governance should help define the proposed system's purpose, success criteria, and boundaries. A structured impact assessment before building surfaces legal, ethical, and technical issues while they are still cheap to fix.
Probability-severity matrix in design review
A probability-severity matrix helps teams rank AI risks by likelihood and impact so review effort can be prioritized. It turns vague risk talk into a structured design-review tool that supports go/no-go and mitigation decisions.
Data provenance vs. lineage
Data provenance records where data came from, while lineage tracks how it moves and transforms through the pipeline. Both are governance controls because they make it possible to demonstrate lawful rights, fitness for purpose, and reproducibility.
Fit for purpose in training data
Fit for purpose means the data is relevant, representative, and adequate for the intended use, not merely available. Governance must verify fitness before training rather than assuming more data always produces a better model.
Lawful rights to collect and use training data
Before training begins, the organization should document its lawful rights to collect and use the data, including licenses, consents, and contractual permissions. Undocumented rights create legal and IP exposure that may block release or trigger remediation costs.
ISO/IEC 42005 impact assessment
ISO/IEC 42005:2025 provides guidance for AI system impact assessments, helping organizations characterize effects on individuals, groups, and society across the lifecycle. It complements ISO/IEC 42001 by supplying the assessment methodology that the management system standard requires.
Release readiness as a governance decision
Release readiness is a governance decision because a system can pass technical metrics yet lack monitoring, escalation paths, documentation, or user safeguards. Governance evidence, not just model metrics, is what makes release defensible.
Model card at release
A model card summarizes intended use, limitations, evaluation results, and other key details for downstream users and reviewers. It supports transparency and more disciplined downstream use than raw technical documentation alone.
Model drift and why it matters
Model drift is the gradual divergence between a model's launch-time behavior and its current behavior as inputs, users, or environment shift. Monitoring and scheduled retraining exist to catch drift before harm accrues.
Red teaming in AI governance
Red teaming is structured adversarial testing that probes an AI system for failure modes standard validation tends to miss. It adds depth to readiness and monitoring evidence by viewing the system from an attacker or abuser perspective.
Threat modeling for AI
Threat modeling systematically enumerates how an AI system could be attacked or misused and which controls would fail in each path. It is most valuable when AI components introduce new entry points or incentives for abuse.
Incident logs with business and user impact
AI governance evaluates incidents by consequences to people, organizations, and systems, not only by the raw bug description. Capturing business and user impact, not just the technical defect, helps prioritize response and improve the control environment.
Frequently Asked Questions
What is the AIGP exam format?
IAPP administers the AIGP as a 100-question multiple-choice exam with a 2.75-hour appointment and a scheduled 15-minute break. Testing is delivered through Pearson VUE, with in-person test centers and OnVUE remote proctoring available, and the current body of knowledge took effect February 2, 2026.
What score do I need to pass the AIGP?
IAPP reports AIGP results on a 100-500 scaled scoring range, and the passing score is 300. The scaled score is not the same as a raw percentage, so candidates cannot simply count correct answers to know whether they passed.
What are the four AIGP blueprint domains?
The AIGP Body of Knowledge 2.1 covers four domains: Foundations of AI Governance (16-20 scored questions), Laws, Standards and Frameworks (19-23), Governing AI Development (21-25), and Governing AI Deployment and Use (21-25). The two largest domains govern development and deployment, so candidates should weight timed practice toward lifecycle scenarios.
How much does the AIGP exam cost?
The AIGP exam fee is $649 for IAPP members and $799 for nonmembers, with retakes priced at $475 (member) and $625 (nonmember). Certification maintenance requires either IAPP membership (which includes the maintenance fee) or a $250 per two-year certification maintenance fee plus continuing privacy and AI governance education.
What changed for AIGP prep in 2026?
The current AIGP body of knowledge took effect February 2, 2026 and explicitly incorporates generative and agentic AI, the South Korean AI Basic Law (effective January 22, 2026), Colorado's amended AI Act (effective June 30, 2026), and the EU AI Act's broad application date of August 2, 2026. Candidates should refresh 2026 regulatory milestones shortly before test day.
Do I need a legal or technical background before taking AIGP?
No formal prerequisite is required to sit for the AIGP exam. The blueprint is cross-functional, so candidates from privacy, legal, security, product, risk, compliance, procurement, and technical roles can all prepare successfully if they study the governance lifecycle, the major legal buckets, and current AI laws and standards.
Explore More IAPP Certifications
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
More From This Family
Videos and articles for deeper review.