Last-minute revision

AIGP Audio Revision

The same 100 essential facts as the printable revision sheet, read aloud. Four episodes, one per AIGP domain, 25 facts each. Listen on the commute, the night before, or the morning of your exam. Free, no login, nothing to install.

Follow on Spotify Prefer to read? Printable sheet →

Domain Ithe Foundations of AI Governance

Full guide →

The OECD and EU AI Act definition of an AI system, the shift from authored rules to learned behaviour and why it produces opacity and probabilistic outputs, harms at the individual, group, organizational and societal levels, AI-specific security threats, the seven characteristics driving the need for governance, the six named responsible-AI principles, governance roles, and the seven pillars of a governance program. Domain I carries 16 to 20 questions.

Domain IIHow Laws, Standards and Frameworks Apply to AI

Full guide →

The heaviest domain for most candidates. GDPR lawful bases, purpose limitation, DPIA triggers, what Article 22 actually says about solely automated decisions, special category data, disparate treatment and disparate impact, NYC Local Law 144, the Colorado AI Act, the EU AI Act risk pyramid and prohibited practices, the Annex III domains, provider obligations, when a deployer becomes a provider, GPAI, the phasing timeline, the NIST AI RMF functions, and the ISO 42001 family.

Domain IIIHow to Govern AI Development

Full guide →

Governing the build. Why governance starts before code is written, what a use case definition captures, how a design-stage impact assessment differs from a DPIA, FRIA and conformity assessment, ethics by design, the probability and severity matrix, the risk mitigation hierarchy, data lineage versus provenance, the full testing suite, train and test split discipline, release as a governance gate, the model card, data drift versus concept drift, red teaming, and the incident response sequence.

Domain IVHow to Govern AI Deployment and Use

Full guide →

From the deployer's seat, where Domain III governs the build. Context factors and workforce readiness, model type axes, cloud versus on-premise versus edge, the four adaptation techniques and when fine-tuning turns a deployer into a provider, what RAG fixes and what it does not, guardrails for agentic systems, vendor contract terms and what a liability disclaimer does not transfer, spotting a silent vendor update, post-market monitoring as a process rather than a dashboard, serious incident duties, and the deactivation control. Domain IV carries 21 to 25 questions and IV.C is the heaviest competency on the exam.

Before you begin: this is revision to reinforce material you have already studied, not a first pass at it. Complete the IAPP-prescribed reading first. These episodes condense what the exam tends to test; they do not guarantee exam success.