Two years ago there was no such thing as an AI governance certification. There are now at least a dozen, several of them sold by training companies that invented the credential and the course on the same afternoon. Four are worth your money, and the right one depends almost entirely on what you already hold.
The short version: if you hold nothing and you sit on the policy, privacy or compliance side, take the IAPP AIGP. If you already hold CISA and audit for a living, AAIA is the cheaper and sharper choice. If you hold CISM or CISSP and you run security controls, AAISM is your bolt-on. If your job is to build or certify an AI management system against a standard, the ISO/IEC 42001 Lead Auditor route is the one employers actually ask for by name.
What the AI Act delay changed, and what it did not
Plenty of the ranking guidance on AI governance certification was written against a timetable that no longer exists, so start here.
The Digital Omnibus on AI came into force on 27 July 2026. It deferred the Annex III high-risk obligations from 2 August 2026 to 2 December 2027, and pushed the Annex I obligations covering AI embedded in products under EU product-safety law out to 2 August 2028.
What was not deferred matters more for hiring. The Article 50 transparency duties, covering chatbot disclosure, AI content marking and deepfake labelling, applied from 2 August 2026 as originally scheduled. The general-purpose AI provider obligations have applied since August 2025, and the Article 5 prohibited-practices regime has been in force since February 2025.
Career tip: The delay moved the compliance cliff, not the compliance work. Conformity assessments for high-risk systems take longer than the eighteen months that were bought, so the organisations doing this properly are hiring now and training now. A credential earned in 2026 lands well before the December 2027 deadline it is aimed at.
IAPP AIGP: the default AI governance certification
The AIGP is the closest thing to an industry standard, and it is the one that shows up most often in job adverts by name. It launched in 2024 and has no prerequisites, which is why career changers from legal, privacy and policy backgrounds gravitate to it.
The exam is three hours long including an optional 15-minute break, and contains 100 multiple-choice questions. Around 30% are attached to case studies. Scoring is scaled from 100 to 500, and 300 is the pass mark. It costs USD 649 for IAPP members and USD 799 for non-members.
Version 2.1 of the Body of Knowledge took effect on 2 February 2026, replacing 2.0.1. The four domains and their published question ranges out of the 85 scored questions are:
| AIGP domain | Scored questions |
|---|---|
| I. Understanding the foundations of AI governance | 16 to 20 |
| II. Understanding how laws, standards and frameworks apply to AI | 19 to 23 |
| III. Understanding how to govern AI development | 21 to 25 |
| IV. Understanding how to govern AI deployment and use | 21 to 25 |
Read that weighting properly before you buy a course. Domains III and IV together account for roughly half the scored exam, and both are about governing systems in practice rather than reciting statute. Candidates who arrive from a pure legal background and revise only Domain II tend to fail, because Domain II is the smallest of the four scored blocks after Domain I.
The certification term is two years. Renewal needs 20 continuing education credits mapped to the AIGP Body of Knowledge, plus a maintenance fee of USD 250 per term for non-members, which is included in membership for members.
Our full AIGP breakdown goes deeper on the domains and the study path.
ISACA AAIA and AAISM: bolt-ons, not starting points
ISACA took a different route. Rather than one broad credential, it built two narrow ones that sit on top of qualifications you already hold. Neither is available to someone starting from scratch, and that gate is the single most common reason people waste time researching them.
AAIA (Advanced in AI Audit) requires an active CISA, or one of a defined list of accountancy qualifications such as CIA, US CPA or ICAEW ACA where the holder works in IT audit or IT advisory. The exam is 90 questions across three domains: AI Governance and Risk at 33%, AI Operations at 46%, and AI Auditing Tools and Techniques at 21%. Note how heavily AI Operations dominates, which surprises auditors expecting a governance paper.
AAISM (Advanced in AI Security Management) requires an active CISM or CISSP. It is also 90 questions across three domains: AI Governance and Program Management at 31%, AI Risk Management at 31%, and AI Technologies and Controls at 38%.
Both cost USD 459 for ISACA members and USD 599 for non-members, plus a USD 50 application processing fee once you pass. You get six months to sit the exam after registering, and five years from passing to apply for the certification itself. AAISM maintenance requires a minimum of 10 CPE hours a year and 30 across the three-year reporting period, in the specialised domain.
That pricing is the quiet argument for these two. If you already hold CISA or CISM, an ISACA bolt-on costs a little over half what the AIGP costs, and it signals depth in a specific function rather than breadth.
We cover both in detail in the AAIA deep dive and the AAISM deep dive.
ISO/IEC 42001 Lead Auditor: the implementer and auditor route
ISO/IEC 42001:2023 is the only certifiable AI management system standard, which makes it the one that turns up in procurement questionnaires. Organisations get certified against it. Individuals get certified to audit or implement it.
The Lead Auditor credential runs through accredited training bodies such as PECB rather than a single vendor exam you can book cold. The PECB course is five days including the exam on day five, and the credential itself requires five years of professional experience with two of those in AI, plus 300 hours of audit activity. Expect to pay roughly USD 1,000 to 2,500 through a training provider, exam included.
That experience requirement is the catch. You can pass the exam long before you qualify for the credential, so treat it as a destination rather than an entry point.
The four compared side by side
| IAPP AIGP | ISACA AAIA | ISACA AAISM | ISO 42001 Lead Auditor | |
|---|---|---|---|---|
| Prerequisite | None | Active CISA or listed accountancy qualification | Active CISM or CISSP | 5 years experience, 2 in AI, 300 audit hours |
| Exam | 100 questions, 3 hours | 90 questions | 90 questions | Sat on day 5 of the course |
| Cost | USD 649 member, USD 799 non-member | USD 459 member, USD 599 non-member | USD 459 member, USD 599 non-member | Roughly USD 1,000 to 2,500 with training |
| Pass mark | Scaled 300 of 100 to 500 | Not published as a scaled figure | Not published as a scaled figure | Set by the training body |
| Renewal | 20 CPE per 2-year term | ISACA CPE policy | 10 CPE per year, 30 per 3 years | PECB maintenance |
| Best for | Policy, privacy, compliance, career changers | IT auditors moving into AI assurance | Security managers owning AI controls | Building or auditing an AIMS |
Which AI governance certification fits your role
Match the credential to the job you want, not the one that scores highest in a listicle.
- Privacy or legal counsel moving into AI: AIGP. No prerequisite, and the Domain II coverage of the EU AI Act, the South Korean AI Basic Law and US state AI laws is the closest fit to the work.
- IT auditor with a CISA: AAIA. Cheaper than AIGP, and hiring managers filling an AI assurance role read CISA plus AAIA as a complete package.
- Security manager with CISM or CISSP: AAISM. The 38% weighting on AI Technologies and Controls is where the actual day job sits. If you are choosing between this and a technical AI security exam, read our SecAI+ versus AAISM comparison.
- GRC generalist deciding where to start at all: get a foundation credential first. Our best GRC certifications guide covers the CISA and CISM routes that unlock the ISACA bolt-ons anyway.
- Consultant selling AI assurance: ISO 42001 Lead Auditor, because clients ask for the standard by number.
One warning on the rest of the market. Search results for AI governance certification are thick with credentials from training companies with no exam development board, no psychometric analysis behind the cut score and no recognition outside their own marketing. A credential nobody has heard of costs the same time as one that hiring managers recognise. Check whether the certifying body existed before 2023, and whether it publishes a body of knowledge you can download and check.
Frequently Asked Questions
Which is the best AI governance certification?
AIGP for most people, because it has no prerequisites and the widest name recognition in job adverts. If you already hold CISA, AAIA is better value at USD 459 for members. If you hold CISM or CISSP, AAISM is the equivalent bolt-on. There is no single best credential across all roles, because three of the four are gated behind qualifications you may not have.
Is AI governance certification worth it?
It is worth it if your role already touches AI risk, privacy, audit or security policy, because the EU AI Act obligations that arrive on 2 December 2027 need people who can evidence conformity work now. It is a weaker bet as a pure career-change credential with no adjacent experience, since employers are hiring governance people with a domain background rather than a certificate alone.
How do I get into AI governance?
Start from the discipline you already have. Privacy and legal professionals take the AIGP directly. Auditors take CISA first, then AAIA. Security professionals take CISM or CISSP first, then AAISM. In every route, the credential formalises existing judgement rather than replacing it, which is why the two ISACA credentials refuse to sell to people without the underlying certification.
Do I need to know the EU AI Act for these exams?
Yes for the AIGP, where Domain II covers current AI laws including the EU AI Act and accounts for 19 to 23 of the 85 scored questions. The ISACA credentials treat regulation as context for risk and control decisions rather than testing statute directly. Learn the Article 50 transparency duties that applied from 2 August 2026, since those were not deferred by the Digital Omnibus.
Does AAISM or AAIA expire?
Both follow ISACA's continuing professional education policy. AAISM requires a minimum of 10 CPE hours a year and 30 across a three-year reporting period, in the specialised domain, along with the annual maintenance fee. The AIGP works on a shorter two-year term needing 20 credits.
Ready to Start Practising?
Reading domain weights tells you what is on the exam. Answering questions under time pressure tells you whether you actually know it, and that gap is where most AI governance candidates lose marks.
CertCrush has a full AAISM practice question bank built around the three published domains and their real weightings, so your revision time goes where the marks are rather than where the reading is easiest.
Create a free account and start practising today.
