1.2 The CIPM Body of Knowledge: Six Domains & How the Exam Is Built

Key Takeaways

  • The CIPM Body of Knowledge v4.2.0 has six domains covering the operational privacy life cycle: framework, governance, assessing data, protecting data, sustaining performance, and requests/incidents.
  • Scored-question ranges (I:14-18, II:12-16, III:12-16, IV:9-13, V:7-9, VI:10-14) sum to less than the 90 total items because every form also carries unscored pretest questions.
  • Approximate weights by midpoint are Domain I ~21%, II ~19%, III ~19%, IV ~15%, V ~11%, VI ~16%.
  • Items are scenario-heavy and management-focused (design/measure/communicate/document/improve), assessing performance indicators at Bloom levels from Remember/Understand up to Evaluate/Create.
  • v4.2.0 supersedes v4.1.0 and refined only performance-indicator wording (AI risk, Privacy by Design, global-rights language, metrics emphasis) — the six domains, 21 competencies, and per-competency question counts are unchanged.
Last updated: August 2026

1.2 The CIPM Body of Knowledge: Six Domains & How the Exam Is Built

Quick Answer: The CIPM Body of Knowledge v4.2.0 is organized into six domains covering the operational privacy life cycle. Scored-question ranges sum to less than 90 because the 90 total items include unscored pretest questions. Items are scenario-heavy and management-focused.

The six domains and their scored ranges

DomainFocusScored itemsApprox. weight
I — Developing a FrameworkStrategy, scope, stakeholders, regulatory landscape, sources of personal information14–18~21%
II — Establishing Program GovernancePolicies, roles, metrics, training, life-cycle processes12–16~19%
III — Assessing DataInventories, flows, gap analysis, vendors, physical/technical controls, M&A12–16~19%
IV — Protecting Personal DataClassification, access, Privacy by Design, safeguards, PETs9–13~15%
V — Sustaining Program PerformanceMetrics, auditing, PIAs/DPIAs/TIAs/LIAs/PTAs, risk mitigation, ethical AI7–9~11%
VI — Responding to Requests & IncidentsRights/consent processes, global legislation, incident handling, post-incident review10–14~16%

The midpoints of these ranges (16/14/14/11/8/12) sum to 75, which is why the approximate weights above are computed against roughly 75 items. The exam has 90 total items, and even the maximum of every domain range sums to only 86 — so some items on every form fall outside the domain counts. Those are unscored pretest questions that IAPP uses to calibrate future forms; the IAPP Certification Candidate Handbook confirms that exams contain both scored and unscored questions and directs candidates to the designation page for the current split, which is why you should treat 75 as a planning approximation rather than a published figure. You cannot identify pretest items, so answer every one as if it counts.

Why the ranges are ranges, not fixed counts

Each exam form is built to a blueprint that allows a range per domain rather than a fixed count. This lets IAPP assemble multiple psychometrically equivalent forms without locking the same 16 Domain-I items into every one. Implication for you: do not budget your study time by assuming Domain I is exactly 18 items. Treat the upper bound as your planning assumption (you could see 18 scored Domain-I items), and treat the lower bound as the floor.

Performance indicators and Bloom levels

Under each domain sit competencies, and under each competency sit performance indicators — granular tasks a privacy manager should be able to perform (for example, "develop a privacy strategy aligned with the business model," or "measure policy compliance through gap analysis"). Items assess proficiency on these indicators, and the cognitive load ranges from Remember/Understand (recall a definition) up through Apply/Analyze (choose the right control for a scenario) to Evaluate/Create (design or judge a program element). The bulk of the exam lives at Apply/Analyze, which is why rote memorization of law citations is a losing strategy.

Scenario-heavy and management-focused

A typical CIPM item is a 1–3 sentence scenario followed by a question that asks what the privacy manager should do — design, measure, communicate, document, prioritize, or improve. It is rarely "which statute regulates X." Expect to be asked things like: given a new product launch in three jurisdictions, which assessment sequence should the manager sequence first; given a vendor with sub-processors in two countries, which contractual and controls evidence should be demanded; given a metric trend, what does it signal about program health. The right answer is usually the best scalable process, not the fastest immediate fix (see §1.3).

What v4.2.0 changed (and did not)

The blueprint currently in force is v4.2.0, approved 16 Jan 2025 and effective Sept 1 2025; its own cover page records that it supersedes v4.1.0. Critically, v4.2.0 did not change the six domains, the 21 competencies, or the per-competency question-count ranges. What it did change is the performance-indicator wording — refining language around AI privacy risk, Privacy by Design, global data-subject-rights terminology, and metrics. Operationally this means an older set of domain-level notes is still structurally valid; the risk is in indicator-level detail (for example, a v4.2.0 item may frame a Privacy by Design principle more precisely than an older flashcard). IAPP reviews the Body of Knowledge annually and commits to announcing content changes at least 90 days before they appear on the exam, so check the blueprint's effective date before trusting any third-party outline.

The operational life cycle, visualized

flowchart LR
    A["Domain I<br/>Develop Framework"] --> B["Domain II<br/>Establish Governance"]
    B --> C["Domain III<br/>Assess Data"]
    C --> D["Domain IV<br/>Protect Data"]
    D --> E["Domain V<br/>Sustain Performance"]
    E --> F["Domain VI<br/>Requests & Incidents"]
    F -. feedback .-> A

The six domains are not isolated topics — they are a life cycle. Domain I sets strategy, II builds the governance skeleton, III assesses what data exists and where it flows, IV applies controls, V measures whether controls work, and VI handles external-facing requests and incidents. The dashed feedback edge matters: incidents and rights-request patterns (VI) and metrics (V) feed back into framework revision (I). Cross-domain scenarios test exactly this loop.

Test Your Knowledge

Which CIPM domain carries the largest scored-question range?

A
B
C
D
Test Your Knowledge

A study buddy says: "v4.2.0 restructured the CIPM domains, so any older notes are obsolete." What is the most accurate correction?

A
B
C
D