AIGP BoK v2.1: What the Official Blueprint Changed

AIGP Body of Knowledge v2.1 is the official map of what the Artificial Intelligence Governance Professional exam measures. The PDF AIGP_BOK_2.1.0_FINAL.pdf is version 2.1, approved by the AIGP Exam Development Board on 9 September 2025, effective 2 February 2026, and it supersedes 2.0.1. Sit on or after that date and this is the outline that counts.

Practice in this bank is mapped to v2.1 because that is the current IAPP text. We are the modern practice system for every AI certification; the BoK remains IAPP’s.

What the BoK is for (IAPP’s own purpose language)

IAPP states that the main purpose of the AIGP BoK is to document the knowledge and skills assessed on the AIGP certification exam. The domains are what an AI governance professional should know and be able to do. The BoK also carries the exam blueprint: the minimum and maximum number of questions from each domain. Stick to those printed bands. Do not treat third-party “percent of the exam” tables as v2.1.

The exam development board maintains the BoK. IAPP notes an annual review, with updates communicated at least 90 days before new content appears.

Approach: generative AI and agentic AI as governance applications

v2.1 keeps the four-domain structure of 2.0.1 and updates the content. The approach says the certification concentrates on AI governance — concepts plus principles, benefits, risks, and oversight — and distills global laws, frameworks, and standards to widely accepted elements.

IAPP writes that it continues to evolve content for changing requirements and the applications they cover, such as generative AI and agentic AI. The program delivers core knowledge to govern AI rather than every niche. Anyone responsible for adopting or managing AI is in scope. That is official framing, not a claim about what IAPP “secretly” wants. A 2.0.1-only deck that never mentions agentic AI is incomplete after 2 February 2026.

Bloom’s Taxonomy on this exam

Performance-indicator verbs (identify, evaluate, implement, define) map to Bloom’s Taxonomy. IAPP exam questions mostly focus on the remember/understand and apply/analyze levels.

The four domains, with official min/max

Question counts below are v2.1 blueprint bands (how many items from each domain can appear), not a single fixed mix.

Domain I — Understanding the foundations of AI governance (min 16, max 20)

Domain I is what AI governance is: common principles and pillars for a program, regardless of industry, sector, or size.

Subdomain bands in the PDF:

  • I.A (4–6): What AI is and why it needs governance — types, risks and harms, characteristics that demand oversight, and common responsible-AI principles.
  • I.B (5–7): Organizational expectations — roles, cross-functional collaboration, training, and how approaches differ by size, maturity, industry, and risk tolerance, including developers, providers, deployers, and users.
  • I.C (6–8): Policies across the AI life cycle, updates to existing privacy/security/IP policies, and third-party risk.

Domain II — Understanding how laws, standards and frameworks apply to AI (min 19, max 23)

Domain II covers existing laws that apply to AI plus AI-specific laws, standards, and frameworks. IAPP names the major elements of current AI laws (for example, the EU AI Act, the South Korean AI Basic Law, and federal and state AI laws that apply to private-sector organizations). The South Korean AI Basic Law is in that official sentence — do not skip it because a 2.0.1 outline never named it.

II.D is 3–5 questions: industry standards and tools. The performance indicators name:

  • OECD principles, framework, policies, and recommended practices for trustworthy AI
  • The NIST AI Risk Management Framework and Playbook (core functions, categories, and subcategories)
  • Core ISO AI standards 22989, 42001, and 42005

ISO 42005 next to 22989 and 42001 is a content update you should be able to place. v2.1 still expects privacy law applied to AI, other existing law (nondiscrimination, consumer protection, product liability, IP), and AI-specific-law elements (risk classification, distinct GPAI-style requirements, enforcement, and provider/deployer/importer/distributor roles).

Domain III — Understanding how to govern AI development (min 21, max 25)

Domain III is the governance professional’s job while an organization designs, builds, trains, tests, and maintains AI systems.

III.C is 8–10 questions on release, monitoring, and maintenance — the heaviest development subdomain. Indicators include the model card and conformity requirements; monitoring, updates, and retraining; red teaming, threat modeling, audits, and security testing; incidents; and public disclosures (technical documentation, instructions for deployers, post-market monitoring plans).

The other Domain III bands cover design/build (impact assessment, risk tools) and data used in training and testing (lineage, provenance, lawful rights, fit-for-purpose).

Domain IV — Understanding how to govern AI deployment and use (min 21, max 25)

Domain IV is selecting a model, then deploying, using, and monitoring it, whether proprietary or third-party. Indicators distinguish classic versus generative models, proprietary versus open source, cloud versus on-premise versus edge, and techniques such as fine-tuning, RAG, and agentic architectures. Deployment governance includes vendor/licensing risk, monitoring, red teaming, secondary-use harms, and controls to deactivate or localize a system.

Domains III and IV share monitoring vocabulary on purpose: development-side release and deployer-side use are different jobs in the BoK.

What v2.1 did not do

v2.1 keeps the four-domain structure of 2.0.1 and updates content. Use the official min/max bands and the named additions: agentic AI in the approach (and agentic architectures under deployment), ISO 42005 in II.D, and the South Korean AI Basic Law in Domain II’s law examples.

Study implications after 2 February 2026

If notes or a course stop at 2.0.1, do not treat them as sufficient for an exam under v2.1. Keep the four-domain skeleton where it still matches. Cover agentic applications, ISO 42005, the South Korean AI Basic Law, and the III.C release/monitoring list from the current PDF.

How to update a plan:

  1. Download the official file from IAPP (AIGP BoK v2.1 PDF) and keep the AIGP program page handy.
  2. Copy the four domain names and the min/max bands into your tracker so practice volume roughly respects 16–20 / 19–23 / 21–25 / 21–25 rather than an invented pie chart.
  3. Search your materials for agentic AI, ISO 42005, and South Korean AI Basic Law. If a phrase is missing, that gap is documented in v2.1, not inferred.
  4. Retire 2.0.1-only outlines that contradict the current performance indicators, especially around release (model card, conformity, red teaming, disclosures) and deployer monitoring.
  5. Practice with items mapped to v2.1 domains. Bloom’s reminder: you need both remember/understand and apply/analyze, so mix definitions with scenarios.

Exam fees live on AIGP exam cost (IAPP store $649 / $799 dated 28 August 2026). Choosing among governance, security-operations, and security-management credentials: AIGP vs SecAI+ vs AAISM.

Practice mapped to v2.1

Try 10 free questions from the bank (items AIGP-FREE-01 through AIGP-FREE-10). Default checkout is Course + questions, $199, which unlocks AIGP + SecAI+ for 12 months. Practice questions alone are $79 and also unlock both banks. Everything is $349, the full kit for both. All-certs subscription is $29/month or $199/year and is what adds future catalogs. The $199 one-time does not add future certs. Those are our products. They are not IAPP’s BoK.

FAQ

What is AIGP BoK v2.1?

IAPP’s official Body of Knowledge and exam blueprint: version 2.1, approved by the AIGP EDB on 9 September 2025, effective 2 February 2026, superseding 2.0.1. It documents knowledge and skills assessed and min/max questions per domain.

When did AIGP BoK v2.1 take effect?

2 February 2026. Materials that only match 2.0.1 are not a complete map after that date.

What are the four AIGP v2.1 domains and their question ranges?

Domain I foundations 16–20; Domain II laws, standards, and frameworks 19–23; Domain III governing development 21–25; Domain IV governing deployment and use 21–25. Those bands are from the official PDF.

What new topics should I expect relative to 2.0.1?

v2.1 keeps four domains and updates content. Study generative AI and agentic AI in the approach, ISO 42005 with 22989 and 42001, and the South Korean AI Basic Law among current AI-law examples (plus federal and state AI laws applying to private-sector organizations).

Can I use 2.0.1-only study materials after 2 February 2026?

Not as your only source. Reuse structure where it still matches; supplement named v2.1 additions and current performance indicators, then practice against the v2.1 blueprint.